Honor user passed on container in nsinit

Docker-DCO-1.1-Signed-off-by: Michael Crosby <michael@crosbymichael.com> (github: crosbymichael)
This commit is contained in:
Michael Crosby 2014-02-24 13:52:56 -08:00
parent 25f62af162
commit 739da85557
1 changed files with 25 additions and 9 deletions

View File

@ -8,6 +8,7 @@ import (
"github.com/dotcloud/docker/pkg/libcontainer/capabilities" "github.com/dotcloud/docker/pkg/libcontainer/capabilities"
"github.com/dotcloud/docker/pkg/libcontainer/network" "github.com/dotcloud/docker/pkg/libcontainer/network"
"github.com/dotcloud/docker/pkg/system" "github.com/dotcloud/docker/pkg/system"
"github.com/dotcloud/docker/pkg/user"
"log" "log"
"os" "os"
"os/exec" "os/exec"
@ -110,7 +111,21 @@ func resolveRootfs(uncleanRootfs string) (string, error) {
} }
func setupUser(container *libcontainer.Container) error { func setupUser(container *libcontainer.Container) error {
// TODO: honor user passed on container if container.User != "" {
uid, gid, suppGids, err := user.GetUserGroupSupplementary(container.User, syscall.Getuid(), syscall.Getgid())
if err != nil {
return err
}
if err := system.Setgroups(suppGids); err != nil {
return err
}
if err := system.Setgid(gid); err != nil {
return err
}
if err := system.Setuid(uid); err != nil {
return err
}
} else {
if err := system.Setgroups(nil); err != nil { if err := system.Setgroups(nil); err != nil {
return err return err
} }
@ -120,6 +135,7 @@ func setupUser(container *libcontainer.Container) error {
if err := system.Setresuid(0, 0, 0); err != nil { if err := system.Setresuid(0, 0, 0); err != nil {
return err return err
} }
}
return nil return nil
} }