Browse Source

Merge branch 'build-image/master'

build-image/master
Claudio Luck 7 months ago
parent
commit
ed024f28bb
10 changed files with 1318 additions and 155 deletions
  1. +32
    -3
      .drone.yml
  2. +3
    -0
      .gitmodules
  3. +1
    -0
      contrib/pEp/pEpLinuxBuilder
  4. +43
    -150
      parts/build/Dockerfile
  5. +141
    -0
      parts/build/Dockerfile.dind
  6. +62
    -0
      parts/build/docker-library/docker-entrypoint.sh
  7. +187
    -0
      parts/build/docker-library/dockerd-entrypoint.sh
  8. +20
    -0
      parts/build/docker-library/modprobe.sh
  9. +828
    -0
      parts/build/seccomp.json
  10. +1
    -2
      src/GNUmakefile

+ 32
- 3
.drone.yml View File

@ -1,7 +1,7 @@
kind: pipeline
type: docker
name: default
steps:
- name: submodules
image: alpine/git
@ -9,8 +9,34 @@ steps:
- env
- git submodule update --init --recursive --remote
- name: build-image
- name: build-image-1
image: plugins/docker
environment:
PLUGIN_DEBUG: true
settings:
# username: test
# password: n0t-This-1
repo: hub.pep.oneon.ch/plugins/docker
build_args:
- DRONE_IMAGE_BUILD_BRANCH=${DRONE_BRANCH#build-image/*}
tags:
- "${DRONE_BRANCH#build-image/*}"
- latest
# - "${DRONE_BRANCH}-${DRONE_COMMIT}"
registry: hub.pep.oneon.ch
dockerfile: parts/build/Dockerfile.dind
cache_from:
- "hub.pep.oneon.ch/plugins/docker:master"
- "hub.pep.oneon.ch/plugins/docker:${DRONE_BRANCH#build-image/*}"
when:
branch:
- build-image/*
- name: build-image-2
image: hub.pep.oneon.ch/plugins/docker
privileged: true
# environment:
# PLUGIN_DEBUG: true
settings:
# username: test
# password: n0t-This-1
@ -33,6 +59,8 @@ steps:
image: "hub.pep.oneon.ch/pe_p/linux-tb-install-alpine-build:${DRONE_BRANCH:-master}"
pull: always
commands:
- /install/bin/wx-config --static --cppflags
- /install/bin/wx-config --static --libs
- _ver_mk=$$(awk '$1 == "VERSION" {print $3}' GNUmakefile)
- export _ver=${DRONE_TAG#Release_}
- export _ver=$${_ver:-$${_ver_mk}}
@ -43,7 +71,8 @@ steps:
- "[ -e plat/lnx/tb_setup ] || cp -v src/tb_setup plat/lnx/tb_setup"
- make -C src/launcher
- cp -v src/launcher/install.run plat/lnx/install.run
- CPPFLAGS="-L/install/lib" make all STATIC=yes OS=lnx VARIANT=unreleased pEp4Tb_release="$${_pEp4Tb_rel}" VERSION="$${_ver}" wx_config=/install/bin/wx-config
#- CPPFLAGS="-L/install/lib" make all STATIC=yes OS=lnx VARIANT=unreleased pEp4Tb_release="$${_pEp4Tb_rel}" VERSION="$${_ver}" wx_config=/install/bin/wx-config
- CPPFLAGS="-L/install/lib" make all STATIC=no OS=lnx VARIANT=unreleased pEp4Tb_release="$${_pEp4Tb_rel}" VERSION="$${_ver}" wx_config=/install/bin/wx-config
# - make webinstall OS=lnx VARIANT=unreleased pEp4Tb_release="$${_pEp4Tb_rel}" VERSION="$${_ver}"
when:
branch:


+ 3
- 0
.gitmodules View File

@ -16,3 +16,6 @@
path = contrib/pEp/pEpForThunderbird
url = https://pep-security.lu/gitlab/thunderbird/pEpForThunderbird.git
branch = master
[submodule "contrib/pEp/pEpLinuxBuilder"]
path = contrib/pEp/pEpLinuxBuilder
url = http://pep-security.lu/gitlab/marcel/peplinuxbuilder.git

+ 1
- 0
contrib/pEp/pEpLinuxBuilder

@ -0,0 +1 @@
Subproject commit 6abd3c3e12074737be9246c1950a2c7a09b485f5

+ 43
- 150
parts/build/Dockerfile View File

@ -1,159 +1,52 @@
FROM alpine
FROM alpine:edge as alpine
# Arguments with defaults
ARG DRONE_IMAGE_BUILD_BRANCH=master
ARG libiconvver=1.16
ARG cairover=1.16.0
ARG pangover=1.48.1
ARG wxWidgetsTag=v3.1.4
ARG p4liTag=${DRONE_IMAGE_BUILD_BRANCH}
ENV DRONE_IMAGE_BUILD_BRANCH ${DRONE_IMAGE_BUILD_BRANCH}
ENV libiconvver ${libiconvver}
ENV cairover ${cairover}
ENV pangover ${pangover}
ENV wxWidgetsTag ${wxWidgetsTag}
ENV p4liTag ${p4liTag}
WORKDIR /root
ADD contrib/get-pip.py /root/get-pip.py
# ADD parts/build/setup.sh /root/setup.sh
# RUN /root/setup.sh
RUN apk add git wget
RUN mkdir -p /root/src /install
WORKDIR /root/src
RUN git clone --branch="${wxWidgetsTag}" --depth=1 https://github.com/wxWidgets/wxWidgets.git
RUN cd wxWidgets && git submodule update --init 3rdparty/catch
RUN git clone --branch="${p4liTag}" --depth=1 https://gitea.pep.foundation/claudio/pEpLinuxSetupForThunderbird.git
RUN cd pEpLinuxSetupForThunderbird && git submodule update --init
RUN wget https://ftp.gnu.org/gnu/libiconv/libiconv-${libiconvver}.tar.gz
RUN wget https://cairographics.org/releases/cairo-${cairover}.tar.xz
RUN wget https://download.gnome.org/sources/pango/${pangover%.*}/pango-${pangover}.tar.xz
RUN tar -xf libiconv-${libiconvver}.tar.gz
RUN tar -xf cairo-${cairover}.tar.xz
RUN tar -xf pango-${pangover}.tar.xz
RUN apk add wxgtk wxgtk-dev build-base meson python2 python2-dev sqlite curl zip
RUN apk add libpng-dev libpng-static libjpeg-turbo-dev libjpeg-turbo-static tiff tiff-dev expat-dev expat-static libx11-dev libx11-static libxau-dev libxcb libxcb-dev libxcb-static doxygen graphviz pango-dev xz zlib-static freetype-static fontconfig-static harfbuzz-static gettext-static glib-static graphite2-static fribidi-static bzip2-static brotli-static pixman-static
RUN python2 /root/get-pip.py
RUN python2 -m pip install nuitka
RUN ip link
RUN ip address
RUN ip route show
# RUN apk add alpine-sdk
# RUN adduser -D build
# RUN addgroup build abuild
# RUN mkdir -p /var/cache/distfiles
# RUN chmod a+w /var/cache/distfiles
# RUN chmod g+w /var/cache/distfiles
RUN adduser -D build
RUN addgroup build abuild
RUN mkdir -p /var/cache/distfiles
RUN chmod a+w /var/cache/distfiles
RUN chmod g+w /var/cache/distfiles
#
# RUN apk add sudo
# RUN echo "build ALL=(ALL) NOPASSWD: ALL" >/etc/sudoers.d/build
# # RUN echo "build ALL=(root) NOPASSWD: /usr/bin/abuild-keygen" >/etc/sudoers.d/build
#
# RUN sed -i.bak -e 's/export JOBS=2/export JOBS=${JOBS-10}/' /etc/abuild.conf
# RUN sed -i.bak -e 's/USE_COLORS=1/#USE_COLORS=1/g' /etc/abuild.conf
#
# USER build
#
# RUN abuild-keygen -a -i -n
#
# RUN git config --global user.name "Build Bot"
# RUN git config --global user.email "build@pep.oneon.ch"
#
# RUN mkdir -p /home/build/src
# RUN [ -d /home/build/src/aports] || git clone https://gitlab.alpinelinux.org/alpine/aports /home/build/src/aports
#
# RUN cd /home/build/src/aports/community/gnu-libiconv
# RUN sed -i.bak -e 's/disable-static/enable-static/' APKBUILD
# RUN abuild
WORKDIR /root/src/libiconv-${libiconvver}
RUN ./configure --prefix=/install --enable-extra-encodings --enable-static
RUN make -j10
RUN make install
WORKDIR /root/src/cairo-${cairover}
RUN ./configure --enable-static --disable-xlib-xrender --disable-xcb-shm --prefix=/install/
# cairo (version 1.16.0 [release]) will be compiled with:
#
# The following surface backends:
# Image: yes (always builtin)
# Recording: yes (always builtin)
# Observer: yes (always builtin)
# Mime: yes (always builtin)
# Tee: no (disabled, use --enable-tee to enable)
# XML: no (disabled, use --enable-xml to enable)
# Xlib: yes
# Xlib Xrender: no (disabled, use --enable-xlib-xrender to enable)
# Qt: no (disabled, use --enable-qt to enable)
# Quartz: no (requires CoreGraphics framework)
# Quartz-image: no (disabled, use --enable-quartz-image to enable)
# XCB: yes
# Win32: no (requires a Win32 platform)
# OS2: no (disabled, use --enable-os2 to enable)
# CairoScript: yes
# PostScript: yes
# PDF: yes
# SVG: yes
# OpenGL: no (disabled, use --enable-gl to enable)
# OpenGL ES 2.0: no (disabled, use --enable-glesv2 to enable)
# OpenGL ES 3.0: no (disabled, use --enable-glesv3 to enable)
# BeOS: no (disabled, use --enable-beos to enable)
# DirectFB: no (disabled, use --enable-directfb to enable)
# OpenVG: no (disabled, use --enable-vg to enable)
# DRM: no (disabled, use --enable-drm to enable)
# Cogl: no (disabled, use --enable-cogl to enable)
#
# The following font backends:
# User: yes (always builtin)
# FreeType: yes
# Fontconfig: yes
# Win32: no (requires a Win32 platform)
# Quartz: no (requires CoreGraphics framework)
#
# The following functions:
# PNG functions: yes
# GLX functions: no (not required by any backend)
# WGL functions: no (not required by any backend)
# EGL functions: no (not required by any backend)
# X11-xcb functions: no (disabled, use --enable-xlib-xcb to enable)
# XCB-shm functions: no (disabled, use --enable-xcb-shm to enable)
#
# The following features and utilities:
# cairo-trace: yes
# cairo-script-interpreter: yes
#
# And the following internal features:
# pthread: yes
# gtk-doc: no
# gcov support: no
# symbol-lookup: no (requires bfd)
# test surfaces: no (disabled, use --enable-test-surfaces to enable)
# ps testing: no (requires libspectre)
# pdf testing: no (requires poppler-glib >= 0.17.4)
# svg testing: no (requires librsvg-2.0 >= 2.35.0)
#
RUN make -j15
RUN make install
WORKDIR /root/src/pango-${pangover}
# Note: missing libthai
RUN meson --prefix=/install/ -Db_staticpic=true -Db_pie=true --wrap-mode=nodownload --auto-features=auto --buildtype=plain -Dintrospection=disabled -Dgtk_doc=false -Ddefault_library=both build
RUN meson compile -j15 -C build
RUN meson install --no-rebuild -C build
WORKDIR /root/src/wxWidgets
RUN ./configure --with-x11 --disable-shared --prefix=/install/ --enable-monolithic --disable-xlocale
RUN make -j15
RUN make install
# WORKDIR /root/src/pEpLinuxSetupForThunderbird/src
# RUN make STATIC=yes wx_config=/install/bin/wx-config
RUN echo http://ftp.halifax.rwth-aachen.de/alpine//edge/main >/etc/apk/repositories
RUN echo http://ftp.halifax.rwth-aachen.de/alpine//edge/community >>/etc/apk/repositories
RUN echo http://ftp.halifax.rwth-aachen.de/alpine//edge/testing >>/etc/apk/repositories
# Following https://pep-security.lu/gitlab/marcel/peplinuxbuilder#installer:
RUN mkdir -p /scripts
COPY contrib/pEp/pEpLinuxBuilder/*.sh /scripts/
ADD contrib/pEp/pEpLinuxBuilder/patches /scripts/
RUN chown -R build: /scripts
WORKDIR /scripts
RUN sed -i.bak -e 's/adduser build//g' ./alpine-installdeps-gui.sh || true
RUN echo set -vx >>./settings.sh
RUN sed -i.bak -e 's/boost1.75-static//g' ./alpine-installdeps-gui.sh || true
RUN sed -i.bak -e 's/capnproto-dev//g' ./alpine-installdeps-gui.sh || true
RUN ./alpine-installdeps-gui.sh
#
USER build
WORKDIR /scripts
# #RUN abuild-keygen -a -i -n
# # RUN git config --global user.name "Build Bot"
# # RUN git config --global user.email "build@pep.oneon.ch"
# # WORKDIR /home/build/src/pEpLinuxBuilder
RUN ./deps-iconv-static.sh
RUN ./deps-cairo-static.sh
RUN ./deps-pango-static.sh
RUN ./tools-wxwidgets.sh
# # RUN ./pEp-tblinux-installer.sh
# # RUN ./deps-python2-static.sh
USER root

+ 141
- 0
parts/build/Dockerfile.dind View File

@ -0,0 +1,141 @@
FROM alpine:edge AS drone-docker-build
RUN apk add --no-cache git make musl-dev go
# Configure Go
ENV GOROOT /usr/lib/go
ENV GOPATH /go
ENV PATH /go/bin:$PATH
RUN mkdir -p ${GOPATH}/src ${GOPATH}/bin
ENV GOOS linux
ENV GOARCH amd64
ENV CGO_ENABLED 0
ENV GO111MODULE on
WORKDIR /root/drone-docker
RUN git clone https://gitea.pep.foundation/claudio/drone-docker.git /root/drone-docker
RUN go build -v -a -tags netgo -o release/linux/amd64/drone-docker ./cmd/drone-docker
# FROM drone/docker AS drone-docker
FROM alpine:edge
RUN apk add --no-cache \
ca-certificates \
# DOCKER_HOST=ssh://... -- https://github.com/docker/cli/pull/1014
openssh-client
# set up nsswitch.conf for Go's "netgo" implementation (which Docker explicitly uses)
# - https://github.com/docker/docker-ce/blob/v17.09.0-ce/components/engine/hack/make.sh#L149
# - https://github.com/golang/go/blob/go1.9.1/src/net/conf.go#L194-L275
# - docker run --rm debian:stretch grep '^hosts:' /etc/nsswitch.conf
RUN [ ! -e /etc/nsswitch.conf ] && echo 'hosts: files dns' > /etc/nsswitch.conf
ENV DOCKER_CHANNEL stable
ENV DOCKER_VERSION 20.10.0
# TODO ENV DOCKER_SHA256
# https://github.com/docker/docker-ce/blob/5b073ee2cf564edee5adca05eee574142f7627bb/components/packaging/static/hash_files !!
# (no SHA file artifacts on download.docker.com yet as of 2017-06-07 though)
RUN set -eux; \
\
# this "case" statement is generated via "update.sh"
apkArch="$(apk --print-arch)"; \
case "$apkArch" in \
# amd64
x86_64) dockerArch='x86_64' ;; \
# arm32v6
armhf) dockerArch='armel' ;; \
# arm32v7
armv7) dockerArch='armhf' ;; \
# arm64v8
aarch64) dockerArch='aarch64' ;; \
*) echo >&2 "error: unsupported architecture ($apkArch)"; exit 1 ;;\
esac; \
\
if ! wget -O docker.tgz "https://download.docker.com/linux/static/${DOCKER_CHANNEL}/${dockerArch}/docker-${DOCKER_VERSION}.tgz"; then \
echo >&2 "error: failed to download 'docker-${DOCKER_VERSION}' from '${DOCKER_CHANNEL}' for '${dockerArch}'"; \
exit 1; \
fi; \
\
tar --extract \
--file docker.tgz \
--strip-components 1 \
--directory /usr/local/bin/ \
; \
rm docker.tgz; \
\
dockerd --version; \
docker --version
# https://github.com/docker/docker/blob/master/project/PACKAGERS.md#runtime-dependencies
RUN set -eux; \
apk add --no-cache \
btrfs-progs \
e2fsprogs \
e2fsprogs-extra \
iptables \
openssl \
shadow-uidmap \
xfsprogs \
xz \
# pigz: https://github.com/moby/moby/pull/35697 (faster gzip implementation)
pigz \
; \
# only install zfs if it's available for the current architecture
# https://git.alpinelinux.org/cgit/aports/tree/main/zfs/APKBUILD?h=3.6-stable#n9 ("all !armhf !ppc64le" as of 2017-11-01)
# "apk info XYZ" exits with a zero exit code but no output when the package exists but not for this arch
if zfs="$(apk info --no-cache --quiet zfs)" && [ -n "$zfs" ]; then \
apk add --no-cache zfs; \
fi
# TODO aufs-tools
# set up subuid/subgid so that "--userns-remap=default" works out-of-the-box
RUN set -x \
&& addgroup -S dockremap \
&& adduser -S -G dockremap dockremap \
&& echo 'dockremap:165536:65536' >> /etc/subuid \
&& echo 'dockremap:165536:65536' >> /etc/subgid
# https://github.com/docker/docker/tree/master/hack/dind
ENV DIND_COMMIT ed89041433a031cafc0a0f19cfe573c31688d377
RUN set -eux; \
wget -O /usr/local/bin/dind "https://raw.githubusercontent.com/docker/docker/${DIND_COMMIT}/hack/dind"; \
chmod +x /usr/local/bin/dind
COPY parts/build/docker-library/modprobe.sh /usr/local/bin/modprobe
COPY parts/build/docker-library/docker-entrypoint.sh /usr/local/bin/
COPY parts/build/docker-library/dockerd-entrypoint.sh /usr/local/bin/
COPY parts/build/seccomp.json /etc/docker/
# COPY --from=drone-docker /bin/drone-docker /bin/drone-docker
COPY --from=drone-docker-build /root/drone-docker/release/linux/amd64/drone-docker /bin/drone-docker
RUN set -x \
&& mv -f /usr/local/bin/dockerd /usr/local/bin/dockerd-bin \
&& echo '#!/bin/sh' >/usr/local/bin/dockerd \
&& echo '/usr/local/bin/dockerd-bin --seccomp-profile /etc/docker/seccomp.json "$@"' >>/usr/local/bin/dockerd \
&& chmod +x /usr/local/bin/dockerd
# RUN mkdir -p /etc/docker
# RUN echo '{ "iptables": false }' >/etc/docker/daemon.json
# https://github.com/docker-library/docker/pull/166
# dockerd-entrypoint.sh uses DOCKER_TLS_CERTDIR for auto-generating TLS certificates
# docker-entrypoint.sh uses DOCKER_TLS_CERTDIR for auto-setting DOCKER_TLS_VERIFY and DOCKER_CERT_PATH
# (For this to work, at least the "client" subdirectory of this path needs to be shared between the client and server containers via a volume, "docker cp", or other means of data sharing.)
ENV DOCKER_TLS_CERTDIR=/certs
# also, ensure the directory pre-exists and has wide enough permissions for "dockerd-entrypoint.sh" to create subdirectories, even when run in "rootless" mode
RUN mkdir /certs /certs/client && chmod 1777 /certs /certs/client
# (doing both /certs and /certs/client so that if Docker does a "copy-up" into a volume defined on /certs/client, it will "do the right thing" by default in a way that still works for rootless users)
ENV DOCKER_HOST=unix:///var/run/docker.sock
VOLUME /var/lib/docker
EXPOSE 2375 2376
ENTRYPOINT ["/usr/local/bin/dockerd-entrypoint.sh", "/bin/drone-docker"]
CMD []

+ 62
- 0
parts/build/docker-library/docker-entrypoint.sh View File

@ -0,0 +1,62 @@
#!/bin/sh
set -eu
set -vx
# first arg is `-f` or `--some-option`
if [ "${1#-}" != "$1" ]; then
set -- docker "$@"
fi
# if our command is a valid Docker subcommand, let's invoke it through Docker instead
# (this allows for "docker run docker ps", etc)
if docker help "$1" > /dev/null 2>&1; then
set -- docker "$@"
fi
_should_tls() {
[ -n "${DOCKER_TLS_CERTDIR:-}" ] \
&& [ -s "$DOCKER_TLS_CERTDIR/client/ca.pem" ] \
&& [ -s "$DOCKER_TLS_CERTDIR/client/cert.pem" ] \
&& [ -s "$DOCKER_TLS_CERTDIR/client/key.pem" ]
}
# if we have no DOCKER_HOST but we do have the default Unix socket (standard or rootless), use it explicitly
if [ -z "${DOCKER_HOST:-}" ] && [ -S /var/run/docker.sock ]; then
export DOCKER_HOST=unix:///var/run/docker.sock
elif [ -z "${DOCKER_HOST:-}" ] && XDG_RUNTIME_DIR="${XDG_RUNTIME_DIR:-/run/user/$(id -u)}" && [ -S "$XDG_RUNTIME_DIR/docker.sock" ]; then
export DOCKER_HOST="unix://$XDG_RUNTIME_DIR/docker.sock"
fi
# if DOCKER_HOST isn't set (no custom setting, no default socket), let's set it to a sane remote value
if [ -z "${DOCKER_HOST:-}" ]; then
if _should_tls || [ -n "${DOCKER_TLS_VERIFY:-}" ]; then
export DOCKER_HOST='tcp://docker:2376'
else
export DOCKER_HOST='tcp://docker:2375'
fi
fi
if [ "${DOCKER_HOST#tcp:}" != "$DOCKER_HOST" ] \
&& [ -z "${DOCKER_TLS_VERIFY:-}" ] \
&& [ -z "${DOCKER_CERT_PATH:-}" ] \
&& _should_tls \
; then
export DOCKER_TLS_VERIFY=1
export DOCKER_CERT_PATH="$DOCKER_TLS_CERTDIR/client"
fi
if [ "$1" = 'dockerd' ]; then
cat >&2 <<-'EOW'
📎 Hey there! It looks like you're trying to run a Docker daemon.
You probably should use the "dind" image variant instead, something like:
docker run --privileged --name some-docker ... docker:dind ...
See https://hub.docker.com/_/docker/ for more documentation and usage examples.
EOW
sleep 3
fi
exec "$@"

+ 187
- 0
parts/build/docker-library/dockerd-entrypoint.sh View File

@ -0,0 +1,187 @@
#!/bin/sh
set -eu
set -vx
_tls_ensure_private() {
local f="$1"; shift
[ -s "$f" ] || openssl genrsa -out "$f" 4096
}
_tls_san() {
{
ip -oneline address | awk '{ gsub(/\/.+$/, "", $4); print "IP:" $4 }'
{
cat /etc/hostname
echo 'docker'
echo 'localhost'
hostname -f
hostname -s
} | sed 's/^/DNS:/'
[ -z "${DOCKER_TLS_SAN:-}" ] || echo "$DOCKER_TLS_SAN"
} | sort -u | xargs printf '%s,' | sed "s/,\$//"
}
_tls_generate_certs() {
local dir="$1"; shift
# if ca/key.pem || !ca/cert.pem, generate CA public if necessary
# if ca/key.pem, generate server public
# if ca/key.pem, generate client public
# (regenerating public certs every startup to account for SAN/IP changes and/or expiration)
# https://github.com/FiloSottile/mkcert/issues/174
local certValidDays='825'
if [ -s "$dir/ca/key.pem" ] || [ ! -s "$dir/ca/cert.pem" ]; then
# if we either have a CA private key or do *not* have a CA public key, then we should create/manage the CA
mkdir -p "$dir/ca"
_tls_ensure_private "$dir/ca/key.pem"
openssl req -new -key "$dir/ca/key.pem" \
-out "$dir/ca/cert.pem" \
-subj '/CN=docker:dind CA' -x509 -days "$certValidDays"
fi
if [ -s "$dir/ca/key.pem" ]; then
# if we have a CA private key, we should create/manage a server key
mkdir -p "$dir/server"
_tls_ensure_private "$dir/server/key.pem"
openssl req -new -key "$dir/server/key.pem" \
-out "$dir/server/csr.pem" \
-subj '/CN=docker:dind server'
cat > "$dir/server/openssl.cnf" <<-EOF
[ x509_exts ]
subjectAltName = $(_tls_san)
EOF
openssl x509 -req \
-in "$dir/server/csr.pem" \
-CA "$dir/ca/cert.pem" \
-CAkey "$dir/ca/key.pem" \
-CAcreateserial \
-out "$dir/server/cert.pem" \
-days "$certValidDays" \
-extfile "$dir/server/openssl.cnf" \
-extensions x509_exts
cp "$dir/ca/cert.pem" "$dir/server/ca.pem"
openssl verify -CAfile "$dir/server/ca.pem" "$dir/server/cert.pem"
fi
if [ -s "$dir/ca/key.pem" ]; then
# if we have a CA private key, we should create/manage a client key
mkdir -p "$dir/client"
_tls_ensure_private "$dir/client/key.pem"
chmod 0644 "$dir/client/key.pem" # openssl defaults to 0600 for the private key, but this one needs to be shared with arbitrary client contexts
openssl req -new \
-key "$dir/client/key.pem" \
-out "$dir/client/csr.pem" \
-subj '/CN=docker:dind client'
cat > "$dir/client/openssl.cnf" <<-'EOF'
[ x509_exts ]
extendedKeyUsage = clientAuth
EOF
openssl x509 -req \
-in "$dir/client/csr.pem" \
-CA "$dir/ca/cert.pem" \
-CAkey "$dir/ca/key.pem" \
-CAcreateserial \
-out "$dir/client/cert.pem" \
-days "$certValidDays" \
-extfile "$dir/client/openssl.cnf" \
-extensions x509_exts
cp "$dir/ca/cert.pem" "$dir/client/ca.pem"
openssl verify -CAfile "$dir/client/ca.pem" "$dir/client/cert.pem"
fi
}
# no arguments passed
# or first arg is `-f` or `--some-option`
if [ "$#" -eq 0 ] || [ "${1#-}" != "$1" ]; then
# set "dockerSocket" to the default "--host" *unix socket* value (for both standard or rootless)
uid="$(id -u)"
if [ "$uid" = '0' ]; then
dockerSocket='unix:///var/run/docker.sock'
else
# if we're not root, we must be trying to run rootless
: "${XDG_RUNTIME_DIR:=/run/user/$uid}"
dockerSocket="unix://$XDG_RUNTIME_DIR/docker.sock"
fi
case "${DOCKER_HOST:-}" in
unix://*)
dockerSocket="$DOCKER_HOST"
;;
esac
# add our default arguments
if [ -n "${DOCKER_TLS_CERTDIR:-}" ] \
&& _tls_generate_certs "$DOCKER_TLS_CERTDIR" \
&& [ -s "$DOCKER_TLS_CERTDIR/server/ca.pem" ] \
&& [ -s "$DOCKER_TLS_CERTDIR/server/cert.pem" ] \
&& [ -s "$DOCKER_TLS_CERTDIR/server/key.pem" ] \
; then
# generate certs and use TLS if requested/possible (default in 19.03+)
set -- dockerd \
--host="$dockerSocket" \
--host=tcp://0.0.0.0:2376 \
--tlsverify \
--tlscacert "$DOCKER_TLS_CERTDIR/server/ca.pem" \
--tlscert "$DOCKER_TLS_CERTDIR/server/cert.pem" \
--tlskey "$DOCKER_TLS_CERTDIR/server/key.pem" \
"$@"
DOCKERD_ROOTLESS_ROOTLESSKIT_FLAGS="${DOCKERD_ROOTLESS_ROOTLESSKIT_FLAGS:-} -p 0.0.0.0:2376:2376/tcp"
else
# TLS disabled (-e DOCKER_TLS_CERTDIR='') or missing certs
set -- dockerd \
--host="$dockerSocket" \
--host=tcp://0.0.0.0:2375 \
"$@"
DOCKERD_ROOTLESS_ROOTLESSKIT_FLAGS="${DOCKERD_ROOTLESS_ROOTLESSKIT_FLAGS:-} -p 0.0.0.0:2375:2375/tcp"
fi
fi
if [ "$1" = 'dockerd' ]; then
# explicitly remove Docker's default PID file to ensure that it can start properly if it was stopped uncleanly (and thus didn't clean up the PID file)
find /run /var/run -iname 'docker*.pid' -delete || :
uid="$(id -u)"
if [ "$uid" != '0' ]; then
# if we're not root, we must be trying to run rootless
if ! command -v rootlesskit > /dev/null; then
echo >&2 "error: attempting to run rootless dockerd but missing 'rootlesskit' (perhaps the 'docker:dind-rootless' image variant is intended?)"
exit 1
fi
user="$(id -un 2>/dev/null || :)"
if ! grep -qE "^($uid${user:+|$user}):" /etc/subuid || ! grep -qE "^($uid${user:+|$user}):" /etc/subgid; then
echo >&2 "error: attempting to run rootless dockerd but missing necessary entries in /etc/subuid and/or /etc/subgid for $uid"
exit 1
fi
: "${XDG_RUNTIME_DIR:=/run/user/$uid}"
export XDG_RUNTIME_DIR
if ! mkdir -p "$XDG_RUNTIME_DIR" || [ ! -w "$XDG_RUNTIME_DIR" ] || ! mkdir -p "$HOME/.local/share/docker" || [ ! -w "$HOME/.local/share/docker" ]; then
echo >&2 "error: attempting to run rootless dockerd but need writable HOME ($HOME) and XDG_RUNTIME_DIR ($XDG_RUNTIME_DIR) for user $uid"
exit 1
fi
if [ -f /proc/sys/kernel/unprivileged_userns_clone ] && unprivClone="$(cat /proc/sys/kernel/unprivileged_userns_clone)" && [ "$unprivClone" != '1' ]; then
echo >&2 "error: attempting to run rootless dockerd but need 'kernel.unprivileged_userns_clone' (/proc/sys/kernel/unprivileged_userns_clone) set to 1"
exit 1
fi
if [ -f /proc/sys/user/max_user_namespaces ] && maxUserns="$(cat /proc/sys/user/max_user_namespaces)" && [ "$maxUserns" = '0' ]; then
echo >&2 "error: attempting to run rootless dockerd but need 'user.max_user_namespaces' (/proc/sys/user/max_user_namespaces) set to a sufficiently large value"
exit 1
fi
# TODO overlay support detection?
exec rootlesskit \
--net="${DOCKERD_ROOTLESS_ROOTLESSKIT_NET:-vpnkit}" \
--mtu="${DOCKERD_ROOTLESS_ROOTLESSKIT_MTU:-1500}" \
--disable-host-loopback \
--port-driver=builtin \
--copy-up=/etc \
--copy-up=/run \
${DOCKERD_ROOTLESS_ROOTLESSKIT_FLAGS:-} \
"$@" --userland-proxy-path=rootlesskit-docker-proxy
elif [ -x '/usr/local/bin/dind' ]; then
# if we have the (mostly defunct now) Docker-in-Docker wrapper script, use it
set -- '/usr/local/bin/dind' "$@"
fi
else
# if it isn't `dockerd` we're trying to run, pass it through `docker-entrypoint.sh` so it gets `DOCKER_HOST` set appropriately too
set -- docker-entrypoint.sh "$@"
fi
exec "$@"

+ 20
- 0
parts/build/docker-library/modprobe.sh View File

@ -0,0 +1,20 @@
#!/bin/sh
set -eu
# "modprobe" without modprobe
# https://twitter.com/lucabruno/status/902934379835662336
# this isn't 100% fool-proof, but it'll have a much higher success rate than simply using the "real" modprobe
# Docker often uses "modprobe -va foo bar baz"
# so we ignore modules that start with "-"
for module; do
if [ "${module#-}" = "$module" ]; then
ip link show "$module" || true
lsmod | grep "$module" || true
fi
done
# remove /usr/local/... from PATH so we can exec the real modprobe as a last resort
export PATH='/usr/sbin:/usr/bin:/sbin:/bin'
exec modprobe "$@"

+ 828
- 0
parts/build/seccomp.json View File

@ -0,0 +1,828 @@
{
"defaultAction": "SCMP_ACT_TRACE",
"archMap": [
{
"architecture": "SCMP_ARCH_X86_64",
"subArchitectures": [
"SCMP_ARCH_X86",
"SCMP_ARCH_X32"
]
},
{
"architecture": "SCMP_ARCH_AARCH64",
"subArchitectures": [
"SCMP_ARCH_ARM"
]
},
{
"architecture": "SCMP_ARCH_MIPS64",
"subArchitectures": [
"SCMP_ARCH_MIPS",
"SCMP_ARCH_MIPS64N32"
]
},
{
"architecture": "SCMP_ARCH_MIPS64N32",
"subArchitectures": [
"SCMP_ARCH_MIPS",
"SCMP_ARCH_MIPS64"
]
},
{
"architecture": "SCMP_ARCH_MIPSEL64",
"subArchitectures": [
"SCMP_ARCH_MIPSEL",
"SCMP_ARCH_MIPSEL64N32"
]
},
{
"architecture": "SCMP_ARCH_MIPSEL64N32",
"subArchitectures": [
"SCMP_ARCH_MIPSEL",
"SCMP_ARCH_MIPSEL64"
]
},
{
"architecture": "SCMP_ARCH_S390X",
"subArchitectures": [
"SCMP_ARCH_S390"
]
}
],
"syscalls": [
{
"names": [
"accept",
"accept4",
"access",
"adjtimex",
"alarm",
"bind",
"brk",
"capget",
"capset",
"chdir",
"chmod",
"chown",
"chown32",
"clock_adjtime",
"clock_adjtime64",
"clock_getres",
"clock_getres_time64",
"clock_gettime",
"clock_gettime64",
"clock_nanosleep",
"clock_nanosleep_time64",
"close",
"close_range",
"connect",
"copy_file_range",
"creat",
"dup",
"dup2",
"dup3",
"epoll_create",
"epoll_create1",
"epoll_ctl",
"epoll_ctl_old",
"epoll_pwait",
"epoll_pwait2",
"epoll_wait",
"epoll_wait_old",
"eventfd",
"eventfd2",
"execve",
"execveat",
"exit",
"exit_group",
"faccessat",
"faccessat2",
"fadvise64",
"fadvise64_64",
"fallocate",
"fanotify_mark",
"fchdir",
"fchmod",
"fchmodat",
"fchown",
"fchown32",
"fchownat",
"fcntl",
"fcntl64",
"fdatasync",
"fgetxattr",
"flistxattr",
"flock",
"fork",
"fremovexattr",
"fsetxattr",
"fstat",
"fstat64",
"fstatat64",
"fstatfs",
"fstatfs64",
"fsync",
"ftruncate",
"ftruncate64",
"futex",
"futex_time64",
"futimesat",
"getcpu",
"getcwd",
"getdents",
"getdents64",
"getegid",
"getegid32",
"geteuid",
"geteuid32",
"getgid",
"getgid32",
"getgroups",
"getgroups32",
"getitimer",
"getpeername",
"getpgid",
"getpgrp",
"getpid",
"getppid",
"getpriority",
"getrandom",
"getresgid",
"getresgid32",
"getresuid",
"getresuid32",
"getrlimit",
"get_robust_list",
"getrusage",
"getsid",
"getsockname",
"getsockopt",
"get_thread_area",
"gettid",
"gettimeofday",
"getuid",
"getuid32",
"getxattr",
"inotify_add_watch",
"inotify_init",
"inotify_init1",
"inotify_rm_watch",
"io_cancel",
"ioctl",
"io_destroy",
"io_getevents",
"io_pgetevents",
"io_pgetevents_time64",
"ioprio_get",
"ioprio_set",
"io_setup",
"io_submit",
"io_uring_enter",
"io_uring_register",
"io_uring_setup",
"ipc",
"kill",
"lchown",
"lchown32",
"lgetxattr",
"link",
"linkat",
"listen",
"listxattr",
"llistxattr",
"_llseek",
"lremovexattr",
"lseek",
"lsetxattr",
"lstat",
"lstat64",
"madvise",
"membarrier",
"memfd_create",
"mincore",
"mkdir",
"mkdirat",
"mknod",
"mknodat",
"mlock",
"mlock2",
"mlockall",
"mmap",
"mmap2",
"mprotect",
"mq_getsetattr",
"mq_notify",
"mq_open",
"mq_timedreceive",
"mq_timedreceive_time64",
"mq_timedsend",
"mq_timedsend_time64",
"mq_unlink",
"mremap",
"msgctl",
"msgget",
"msgrcv",
"msgsnd",
"msync",
"munlock",
"munlockall",
"munmap",
"nanosleep",
"newfstatat",
"_newselect",
"open",
"openat",
"openat2",
"pause",
"pidfd_open",
"pidfd_send_signal",
"pipe",
"pipe2",
"poll",
"ppoll",
"ppoll_time64",
"prctl",
"pread64",
"preadv",
"preadv2",
"prlimit64",
"pselect6",
"pselect6_time64",
"pwrite64",
"pwritev",
"pwritev2",
"read",
"readahead",
"readlink",
"readlinkat",
"readv",
"recv",
"recvfrom",
"recvmmsg",
"recvmmsg_time64",
"recvmsg",
"remap_file_pages",
"removexattr",
"rename",
"renameat",
"renameat2",
"restart_syscall",
"rmdir",
"rseq",
"rt_sigaction",
"rt_sigpending",
"rt_sigprocmask",
"rt_sigqueueinfo",
"rt_sigreturn",
"rt_sigsuspend",
"rt_sigtimedwait",
"rt_sigtimedwait_time64",
"rt_tgsigqueueinfo",
"sched_getaffinity",
"sched_getattr",
"sched_getparam",
"sched_get_priority_max",
"sched_get_priority_min",
"sched_getscheduler",
"sched_rr_get_interval",
"sched_rr_get_interval_time64",
"sched_setaffinity",
"sched_setattr",
"sched_setparam",
"sched_setscheduler",
"sched_yield",
"seccomp",
"select",
"semctl",
"semget",
"semop",
"semtimedop",
"semtimedop_time64",
"send",
"sendfile",
"sendfile64",
"sendmmsg",
"sendmsg",
"sendto",
"setfsgid",
"setfsgid32",
"setfsuid",
"setfsuid32",
"setgid",
"setgid32",
"setgroups",
"setgroups32",
"setitimer",
"setpgid",
"setpriority",
"setregid",
"setregid32",
"setresgid",
"setresgid32",
"setresuid",
"setresuid32",
"setreuid",
"setreuid32",
"setrlimit",
"set_robust_list",
"setsid",
"setsockopt",
"set_thread_area",
"set_tid_address",
"setuid",
"setuid32",
"setxattr",
"shmat",
"shmctl",
"shmdt",
"shmget",
"shutdown",
"sigaltstack",
"signalfd",
"signalfd4",
"sigprocmask",
"sigreturn",
"socket",
"socketcall",
"socketpair",
"splice",
"stat",
"stat64",
"statfs",
"statfs64",
"statx",
"symlink",
"symlinkat",
"sync",
"sync_file_range",
"syncfs",
"sysinfo",
"tee",
"tgkill",
"time",
"timer_create",
"timer_delete",
"timer_getoverrun",
"timer_gettime",
"timer_gettime64",
"timer_settime",
"timer_settime64",
"timerfd_create",
"timerfd_gettime",
"timerfd_gettime64",
"timerfd_settime",
"timerfd_settime64",
"times",
"tkill",
"truncate",
"truncate64",
"ugetrlimit",
"umask",
"uname",
"unlink",
"unlinkat",
"utime",
"utimensat",
"utimensat_time64",
"utimes",
"vfork",
"vmsplice",
"wait4",
"waitid",
"waitpid",
"write",
"writev"
],
"action": "SCMP_ACT_ALLOW",
"args": [],
"comment": "",
"includes": {},
"excludes": {}
},
{
"names": [
"process_vm_readv",
"process_vm_writev",
"ptrace"
],
"action": "SCMP_ACT_ALLOW",
"args": null,
"comment": "",
"includes": {
"minKernel": "4.8"
},
"excludes": {}
},
{
"names": [
"personality"
],
"action": "SCMP_ACT_ALLOW",
"args": [
{
"index": 0,
"value": 0,
"op": "SCMP_CMP_EQ"
}
],
"comment": "",
"includes": {},
"excludes": {}
},
{
"names": [
"personality"
],
"action": "SCMP_ACT_ALLOW",
"args": [
{
"index": 0,
"value": 8,
"op": "SCMP_CMP_EQ"
}
],
"comment": "",
"includes": {},
"excludes": {}
},
{
"names": [
"personality"
],
"action": "SCMP_ACT_ALLOW",
"args": [
{
"index": 0,
"value": 131072,
"op": "SCMP_CMP_EQ"
}
],
"comment": "",
"includes": {},
"excludes": {}
},
{
"names": [
"personality"
],
"action": "SCMP_ACT_ALLOW",
"args": [
{
"index": 0,
"value": 131080,
"op": "SCMP_CMP_EQ"
}
],
"comment": "",
"includes": {},
"excludes": {}
},
{
"names": [
"personality"
],
"action": "SCMP_ACT_ALLOW",
"args": [
{
"index": 0,
"value": 4294967295,
"op": "SCMP_CMP_EQ"
}
],
"comment": "",
"includes": {},
"excludes": {}
},
{
"names": [
"sync_file_range2"
],
"action": "SCMP_ACT_ALLOW",
"args": [],
"comment": "",
"includes": {
"arches": [
"ppc64le"
]
},
"excludes": {}
},
{
"names": [
"arm_fadvise64_64",
"arm_sync_file_range",
"sync_file_range2",
"breakpoint",
"cacheflush",
"set_tls"
],
"action": "SCMP_ACT_ALLOW",
"args": [],
"comment": "",
"includes": {
"arches": [
"arm",
"arm64"
]
},
"excludes": {}
},
{
"names": [
"arch_prctl"
],
"action": "SCMP_ACT_ALLOW",
"args": [],
"comment": "",
"includes": {
"arches": [
"amd64",
"x32"
]
},
"excludes": {}
},
{
"names": [
"modify_ldt"
],
"action": "SCMP_ACT_ALLOW",
"args": [],
"comment": "",
"includes": {
"arches": [
"amd64",
"x32",
"x86"
]
},
"excludes": {}
},
{
"names": [
"s390_pci_mmio_read",
"s390_pci_mmio_write",
"s390_runtime_instr"
],
"action": "SCMP_ACT_ALLOW",
"args": [],
"comment": "",
"includes": {
"arches": [
"s390",
"s390x"
]
},
"excludes": {}
},
{
"names": [
"open_by_handle_at"
],
"action": "SCMP_ACT_ALLOW",
"args": [],
"comment": "",
"includes": {
"caps": [
"CAP_DAC_READ_SEARCH"
]
},
"excludes": {}
},
{
"names": [
"bpf",
"clone",
"fanotify_init",
"fsconfig",
"fsmount",
"fsopen",
"fspick",
"lookup_dcookie",
"mount",
"move_mount",
"name_to_handle_at",
"open_tree",
"perf_event_open",
"quotactl",
"setdomainname",
"sethostname",
"setns",
"syslog",
"umount",
"umount2",
"unshare"
],
"action": "SCMP_ACT_ALLOW",
"args": [],
"comment": "",
"includes": {
"caps": [
"CAP_SYS_ADMIN"
]
},
"excludes": {}
},
{
"names": [
"clone"
],
"action": "SCMP_ACT_ALLOW",
"args": [
{
"index": 0,
"value": 2114060288,
"op": "SCMP_CMP_MASKED_EQ"
}
],
"comment": "",
"includes": {},
"excludes": {
"caps": [
"CAP_SYS_ADMIN"
],
"arches": [
"s390",
"s390x"
]
}
},
{
"names": [
"clone"
],
"action": "SCMP_ACT_ALLOW",
"args": [
{
"index": 1,
"value": 2114060288,
"op": "SCMP_CMP_MASKED_EQ"
}
],
"comment": "s390 parameter ordering for clone is different",
"includes": {
"arches": [
"s390",
"s390x"
]
},
"excludes": {
"caps": [
"CAP_SYS_ADMIN"
]
}
},
{
"names": [
"reboot"
],
"action": "SCMP_ACT_ALLOW",
"args": [],
"comment": "",
"includes": {
"caps": [
"CAP_SYS_BOOT"
]
},
"excludes": {}
},
{
"names": [
"chroot"
],
"action": "SCMP_ACT_ALLOW",
"args": [],
"comment": "",
"includes": {
"caps": [
"CAP_SYS_CHROOT"
]
},
"excludes": {}
},
{
"names": [
"delete_module",
"init_module",
"finit_module"
],
"action": "SCMP_ACT_ALLOW",
"args": [],
"comment": "",
"includes": {
"caps": [
"CAP_SYS_MODULE"
]
},
"excludes": {}
},
{
"names": [
"acct"
],
"action": "SCMP_ACT_ALLOW",
"args": [],
"comment": "",
"includes": {
"caps": [
"CAP_SYS_PACCT"
]
},
"excludes": {}
},
{
"names": [
"kcmp",
"pidfd_getfd",
"process_madvise",
"process_vm_readv",
"process_vm_writev",
"ptrace"
],
"action": "SCMP_ACT_ALLOW",
"args": [],
"comment": "",
"includes": {
"caps": [
"CAP_SYS_PTRACE"
]
},
"excludes": {}
},
{
"names": [
"iopl",
"ioperm"
],
"action": "SCMP_ACT_ALLOW",
"args": [],
"comment": "",
"includes": {
"caps": [
"CAP_SYS_RAWIO"
]
},
"excludes": {}
},
{
"names": [
"settimeofday",
"stime",
"clock_settime"
],
"action": "SCMP_ACT_ALLOW",
"args": [],
"comment": "",
"includes": {
"caps": [
"CAP_SYS_TIME"
]
},
"excludes": {}
},
{
"names": [
"vhangup"
],
"action": "SCMP_ACT_ALLOW",
"args": [],
"comment": "",
"includes": {
"caps": [
"CAP_SYS_TTY_CONFIG"
]
},
"excludes": {}
},
{
"names": [
"get_mempolicy",
"mbind",
"set_mempolicy"
],
"action": "SCMP_ACT_ALLOW",
"args": [],
"comment": "",
"includes": {
"caps": [
"CAP_SYS_NICE"
]
},
"excludes": {}
},
{
"names": [
"syslog"
],
"action": "SCMP_ACT_ALLOW",
"args": [],
"comment": "",
"includes": {
"caps": [
"CAP_SYSLOG"
]
},
"excludes": {}
}
]
}

+ 1
- 2
src/GNUmakefile View File

@ -18,7 +18,7 @@ LDLIBS := -lutil $(LDLIBS)
#
ifeq ($(STATIC),yes)
CPPFLAGS := $(shell $(wx_config) --static --cppflags) $(CPPFLAGS)
LDLIBS := --static $(shell $(wx_config) --static --libs --linkdeps) $(LDLIBS) -lxcb -lXau -lXdmcp
LDLIBS := --static $(shell $(wx_config) --static --libs) $(LDLIBS) -lxcb -lXau -lXdmcp
else
CPPFLAGS := $(shell $(wx_config) --cppflags) $(CPPFLAGS)
LDLIBS := $(shell $(wx_config) --libs) $(LDLIBS)
@ -48,4 +48,3 @@ clean:
update-pot:
xgettext -d tb_setup -s --keyword=_ -p ../po -o tb_setup.pot $$(find ./ -name '*.cc' -print)

Loading…
Cancel
Save