- include/container.h: document struct fields and constants - src/main.c: explain argument parsing, clone flow, parent/child roles - src/mount.c: describe 6-step mount isolation process - src/cgroup.c: explain cgroup data structures and resource setup/cleanup - src/capabilities.c: document capability drop (bounding + inheritable) - src/seccomp.c: explain each seccomp rule's security purpose - src/userns.c: describe parent-child sync and uid_map/gid_map format - src/hostname.c: document tarot card random naming scheme
54 lines
1.4 KiB
C
54 lines
1.4 KiB
C
/* container.h — 容器核心共享定义
|
|
*
|
|
* 包含所有模块共用的结构体、常量和系统头文件。
|
|
* 每个模块的 .c 文件都 include 此头文件。
|
|
*/
|
|
|
|
#ifndef CONTAINER_H
|
|
#define CONTAINER_H
|
|
|
|
#define _GNU_SOURCE
|
|
#include <errno.h>
|
|
#include <fcntl.h>
|
|
#include <grp.h>
|
|
#include <pwd.h>
|
|
#include <sched.h>
|
|
#include <stdio.h>
|
|
#include <stdlib.h>
|
|
#include <string.h>
|
|
#include <time.h>
|
|
#include <unistd.h>
|
|
#include <sys/mount.h>
|
|
#include <sys/prctl.h>
|
|
#include <sys/resource.h>
|
|
#include <sys/socket.h>
|
|
#include <sys/stat.h>
|
|
#include <sys/syscall.h>
|
|
#include <sys/sysmacros.h>
|
|
#include <sys/utsname.h>
|
|
#include <sys/wait.h>
|
|
#include <linux/capability.h>
|
|
#include <linux/limits.h>
|
|
|
|
/* clone() 子进程栈大小 */
|
|
#define STACK_SIZE (1024 * 1024)
|
|
|
|
/* User Namespace UID/GID 映射:容器内 0 映射到宿主机 10000~11999 */
|
|
#define USERNS_OFFSET 10000
|
|
#define USERNS_COUNT 2000
|
|
|
|
/* 容器内最大打开文件描述符数 */
|
|
#define FD_COUNT 64
|
|
|
|
/* 子进程配置,由 main() 填充,传递给 child() */
|
|
struct child_config {
|
|
int argc; /* -c 后面命令的参数个数 */
|
|
uid_t uid; /* -u 指定的容器内 UID */
|
|
int fd; /* 父子进程通信用的 socket fd */
|
|
char *hostname; /* 容器主机名 */
|
|
char **argv; /* -c 后面的命令及参数 */
|
|
char *mount_dir; /* -m 指定的 rootfs 路径 */
|
|
};
|
|
|
|
#endif
|