Compare commits
4
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
cdbe3ab0a4 | ||
|
|
a8f1cdb445 | ||
|
|
ecb3003ba4 | ||
|
|
d3861f82d4 |
@@ -1583,7 +1583,7 @@ func containerSpecReading(r *declaration.Container, declares, reads map[string]s
|
|||||||
for _, n := range r.Networks {
|
for _, n := range r.Networks {
|
||||||
b.WriteString("also-on " + n + "\n")
|
b.WriteString("also-on " + n + "\n")
|
||||||
}
|
}
|
||||||
// And the capabilities it was granted (ADR 0169): one gained or dropped is a different
|
// And the capabilities it was granted (ADR 0170): one gained or dropped is a different
|
||||||
// container, and the runtime cannot change a running one's.
|
// container, and the runtime cannot change a running one's.
|
||||||
for _, c := range r.Capabilities {
|
for _, c := range r.Capabilities {
|
||||||
b.WriteString("cap " + c + "\n")
|
b.WriteString("cap " + c + "\n")
|
||||||
|
|||||||
@@ -135,7 +135,7 @@ func TestALeftOutModuleIsNeitherRemovedNorForgotten(t *testing.T) {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
// A container's capabilities reach the runtime and are part of its spec (novox/hq ADR 0169).
|
// A container's capabilities reach the runtime and are part of its spec (novox/hq ADR 0170).
|
||||||
func TestACapabilityReachesTheRuntimeAndTheSpec(t *testing.T) {
|
func TestACapabilityReachesTheRuntimeAndTheSpec(t *testing.T) {
|
||||||
var ran []string
|
var ran []string
|
||||||
run := func(_ context.Context, name string, args ...string) (string, error) {
|
run := func(_ context.Context, name string, args ...string) (string, error) {
|
||||||
|
|||||||
@@ -941,7 +941,7 @@ type Container struct {
|
|||||||
Dns []string `json:"dns,omitempty"`
|
Dns []string `json:"dns,omitempty"`
|
||||||
|
|
||||||
// Capabilities are the Linux capabilities this container is granted beyond the runtime's
|
// Capabilities are the Linux capabilities this container is granted beyond the runtime's
|
||||||
// default set, by name (novox/hq ADR 0169): a holder's runtime that changes the machine's packet
|
// default set, by name (novox/hq ADR 0170): a holder's runtime that changes the machine's packet
|
||||||
// filter asks for NET_ADMIN. Exactly these, named in the spec so a change recreates the
|
// filter asks for NET_ADMIN. Exactly these, named in the spec so a change recreates the
|
||||||
// container; a privileged container stays undeclarable.
|
// container; a privileged container stays undeclarable.
|
||||||
Capabilities []string `json:"capabilities,omitempty"`
|
Capabilities []string `json:"capabilities,omitempty"`
|
||||||
|
|||||||
@@ -505,7 +505,7 @@ func TestKeptNetworksAndLeftOutModulesAreReadStrictly(t *testing.T) {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
// A container may ask for a capability by name, and nothing else (novox/hq ADR 0169).
|
// A container may ask for a capability by name, and nothing else (novox/hq ADR 0170).
|
||||||
func TestACapabilityIsNamedOrRefused(t *testing.T) {
|
func TestACapabilityIsNamedOrRefused(t *testing.T) {
|
||||||
image := "postgres@sha256:" + strings.Repeat("a", 64)
|
image := "postgres@sha256:" + strings.Repeat("a", 64)
|
||||||
d, err := Parse([]byte(`{"declaration":1,"resources":[
|
d, err := Parse([]byte(`{"declaration":1,"resources":[
|
||||||
|
|||||||
@@ -15,6 +15,9 @@ const (
|
|||||||
CapServiceManager = "service-manager"
|
CapServiceManager = "service-manager"
|
||||||
CapFirewall = "firewall"
|
CapFirewall = "firewall"
|
||||||
CapOverlay = "overlay"
|
CapOverlay = "overlay"
|
||||||
|
// CapVirtualisation is a running virtualisation daemon: what the lab raises its machines on
|
||||||
|
// (novox/hq ADR 0172), and what grants a module the daemon's socket.
|
||||||
|
CapVirtualisation = "virtualisation"
|
||||||
CapGraphicalSession = "graphical-session"
|
CapGraphicalSession = "graphical-session"
|
||||||
// CapSeat is hardware: somewhere a display server COULD run. CapGraphicalSession above is
|
// CapSeat is hardware: somewhere a display server COULD run. CapGraphicalSession above is
|
||||||
// state: whether one IS running. Assignment needs the first.
|
// state: whether one IS running. Assignment needs the first.
|
||||||
@@ -205,6 +208,11 @@ func Default(runner Runner) []Detector {
|
|||||||
why: "lists the ruleset — needs the tool AND the privilege to use it",
|
why: "lists the ruleset — needs the tool AND the privilege to use it",
|
||||||
runner: runner,
|
runner: runner,
|
||||||
},
|
},
|
||||||
|
commandCapability{
|
||||||
|
name: CapVirtualisation, command: "incus", args: []string{"info"},
|
||||||
|
why: "asks the virtualisation daemon about itself — a running daemon, not an installed client",
|
||||||
|
runner: runner,
|
||||||
|
},
|
||||||
commandCapability{
|
commandCapability{
|
||||||
name: CapOverlay, command: "wg", args: []string{"show", "interfaces"},
|
name: CapOverlay, command: "wg", args: []string{"show", "interfaces"},
|
||||||
why: "asks the kernel for interfaces — needs the module, not just the tool",
|
why: "asks the kernel for interfaces — needs the module, not just the tool",
|
||||||
|
|||||||
Reference in New Issue
Block a user