Add comments to all source and header files

- include/container.h: document struct fields and constants
- src/main.c: explain argument parsing, clone flow, parent/child roles
- src/mount.c: describe 6-step mount isolation process
- src/cgroup.c: explain cgroup data structures and resource setup/cleanup
- src/capabilities.c: document capability drop (bounding + inheritable)
- src/seccomp.c: explain each seccomp rule's security purpose
- src/userns.c: describe parent-child sync and uid_map/gid_map format
- src/hostname.c: document tarot card random naming scheme
This commit is contained in:
2026-07-23 15:48:33 +08:00
parent 3d62194fec
commit f21cbe0574
8 changed files with 238 additions and 41 deletions
+18 -6
View File
@@ -1,3 +1,9 @@
/* container.h — 容器核心共享定义
*
* 包含所有模块共用的结构体、常量和系统头文件。
* 每个模块的 .c 文件都 include 此头文件。
*/
#ifndef CONTAINER_H
#define CONTAINER_H
@@ -24,18 +30,24 @@
#include <linux/capability.h>
#include <linux/limits.h>
/* clone() 子进程栈大小 */
#define STACK_SIZE (1024 * 1024)
/* User Namespace UID/GID 映射:容器内 0 映射到宿主机 10000~11999 */
#define USERNS_OFFSET 10000
#define USERNS_COUNT 2000
/* 容器内最大打开文件描述符数 */
#define FD_COUNT 64
/* 子进程配置,由 main() 填充,传递给 child() */
struct child_config {
int argc;
uid_t uid;
int fd;
char *hostname;
char **argv;
char *mount_dir;
int argc; /* -c 后面命令的参数个数 */
uid_t uid; /* -u 指定的容器内 UID */
int fd; /* 父子进程通信用的 socket fd */
char *hostname; /* 容器主机名 */
char **argv; /* -c 后面的命令及参数 */
char *mount_dir; /* -m 指定的 rootfs 路径 */
};
#endif