Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
21 changes: 10 additions & 11 deletions packages/orchestrator/pkg/sandbox/fc/process.go
Original file line number Diff line number Diff line change
Expand Up @@ -193,15 +193,20 @@ func NewProcess(
}

cmd := exec.CommandContext(execCtx,
"unshare",
"-m",
"--",
"bash",
"-c",
startScript.Value,
)

p := &Process{
cmd.SysProcAttr = &syscall.SysProcAttr{
Setsid: true, // Create a new session
Unshareflags: syscall.CLONE_NEWNS, // Create a new mount namespace.
// Note: unlike `unshare -m` (util-linux >= 2.27), CLONE_NEWNS does NOT automatically
// set MS_PRIVATE propagation. Private isolation is ensured by `mount --make-rprivate /`
// as the first command in both startScriptV1 and startScriptV2.
}

return &Process{
Versions: versions,
Exit: utils.NewErrorOnce(),
cmd: cmd,
Expand All @@ -215,13 +220,7 @@ func NewProcess(

kernelPath: startScript.KernelPath,
rootfsPath: startScript.RootfsPath,
}

cmd.SysProcAttr = &syscall.SysProcAttr{
Setsid: true, // Create a new session
}

return p, nil
}, nil
}

func (p *Process) configure(
Expand Down
14 changes: 10 additions & 4 deletions packages/orchestrator/pkg/sandbox/fc/script_builder.go
Original file line number Diff line number Diff line change
Expand Up @@ -10,6 +10,7 @@ import (

"github.com/e2b-dev/infra/packages/orchestrator/pkg/cfg"
"github.com/e2b-dev/infra/packages/orchestrator/pkg/sandbox/artifact"
"github.com/e2b-dev/infra/packages/orchestrator/pkg/sandbox/network"
"github.com/e2b-dev/infra/packages/shared/pkg/storage"
)

Expand All @@ -25,7 +26,7 @@ type startScriptArgs struct {
DeprecatedSandboxRootfsDir string
SandboxRootfsFile string

NamespaceID string
NetNamespacePath string
FirecrackerPath string
FirecrackerSocket string
}
Expand All @@ -42,6 +43,11 @@ type StartScriptResult struct {
KernelPath string
}

// startScriptV1 and startScriptV2 begin with `mount --make-rprivate /` to recursively
// set MS_PRIVATE on all inherited mount points. This is the explicit equivalent of what
// `unshare -m` (util-linux >= 2.27) does automatically before exec. Without this step,
// the new mount namespace created by CLONE_NEWNS would still inherit shared propagation
// from the parent (verified: 80 shared mount points on this host without it, 0 after).
const startScriptV1 = `mount --make-rprivate / &&

mount -t tmpfs tmpfs {{ .DeprecatedSandboxRootfsDir }} -o X-mount.mkdir &&
Expand All @@ -50,7 +56,7 @@ ln -s {{ .HostRootfsPath }} {{ .DeprecatedSandboxRootfsDir }}/{{ .SandboxRootfsF
mount -t tmpfs tmpfs {{ .SandboxDir }}/{{ .SandboxKernelDir }} -o X-mount.mkdir &&
ln -s {{ .HostKernelPath }} {{ .SandboxDir }}/{{ .SandboxKernelDir }}/{{ .SandboxKernelFile }} &&

ip netns exec {{ .NamespaceID }} {{ .FirecrackerPath }} --api-sock {{ .FirecrackerSocket }}`
nsenter --net={{ .NetNamespacePath }} -- {{ .FirecrackerPath }} --api-sock {{ .FirecrackerSocket }}`

const startScriptV2 = `mount --make-rprivate / &&
mount -t tmpfs tmpfs {{ .SandboxDir }} -o X-mount.mkdir &&
Expand All @@ -60,7 +66,7 @@ ln -s {{ .HostRootfsPath }} {{ .SandboxDir }}/{{ .SandboxRootfsFile }} &&
mkdir -p {{ .SandboxDir }}/{{ .SandboxKernelDir }} &&
ln -s {{ .HostKernelPath }} {{ .SandboxDir }}/{{ .SandboxKernelDir }}/{{ .SandboxKernelFile }} &&

ip netns exec {{ .NamespaceID }} {{ .FirecrackerPath }} --api-sock {{ .FirecrackerSocket }}`
nsenter --net={{ .NetNamespacePath }} -- {{ .FirecrackerPath }} --api-sock {{ .FirecrackerSocket }}`

// StartScriptBuilder handles the creation and execution of firecracker start scripts
type StartScriptBuilder struct {
Expand Down Expand Up @@ -103,7 +109,7 @@ func (sb *StartScriptBuilder) buildArgs(
SandboxRootfsFile: artifact.RootfsFileName,

// FC
NamespaceID: namespaceID,
NetNamespacePath: filepath.Join(network.NetNamespacesDir, namespaceID),
FirecrackerPath: versions.FirecrackerPath(sb.builderConfig),
FirecrackerSocket: files.SandboxFirecrackerSocketPath(),
}
Expand Down
Loading