Add comments to all source and header files
- include/container.h: document struct fields and constants - src/main.c: explain argument parsing, clone flow, parent/child roles - src/mount.c: describe 6-step mount isolation process - src/cgroup.c: explain cgroup data structures and resource setup/cleanup - src/capabilities.c: document capability drop (bounding + inheritable) - src/seccomp.c: explain each seccomp rule's security purpose - src/userns.c: describe parent-child sync and uid_map/gid_map format - src/hostname.c: document tarot card random naming scheme
This commit is contained in:
+18
-6
@@ -1,3 +1,9 @@
|
||||
/* container.h — 容器核心共享定义
|
||||
*
|
||||
* 包含所有模块共用的结构体、常量和系统头文件。
|
||||
* 每个模块的 .c 文件都 include 此头文件。
|
||||
*/
|
||||
|
||||
#ifndef CONTAINER_H
|
||||
#define CONTAINER_H
|
||||
|
||||
@@ -24,18 +30,24 @@
|
||||
#include <linux/capability.h>
|
||||
#include <linux/limits.h>
|
||||
|
||||
/* clone() 子进程栈大小 */
|
||||
#define STACK_SIZE (1024 * 1024)
|
||||
|
||||
/* User Namespace UID/GID 映射:容器内 0 映射到宿主机 10000~11999 */
|
||||
#define USERNS_OFFSET 10000
|
||||
#define USERNS_COUNT 2000
|
||||
|
||||
/* 容器内最大打开文件描述符数 */
|
||||
#define FD_COUNT 64
|
||||
|
||||
/* 子进程配置,由 main() 填充,传递给 child() */
|
||||
struct child_config {
|
||||
int argc;
|
||||
uid_t uid;
|
||||
int fd;
|
||||
char *hostname;
|
||||
char **argv;
|
||||
char *mount_dir;
|
||||
int argc; /* -c 后面命令的参数个数 */
|
||||
uid_t uid; /* -u 指定的容器内 UID */
|
||||
int fd; /* 父子进程通信用的 socket fd */
|
||||
char *hostname; /* 容器主机名 */
|
||||
char **argv; /* -c 后面的命令及参数 */
|
||||
char *mount_dir; /* -m 指定的 rootfs 路径 */
|
||||
};
|
||||
|
||||
#endif
|
||||
|
||||
Reference in New Issue
Block a user