1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
|
/*
* unshare(1) - command-line interface for unshare(2)
*
* Copyright (C) 2009 Mikhail Gusarov <dottedmag@dottedmag.net>
*
* This program is free software; you can redistribute it and/or modify it
* under the terms of the GNU General Public License as published by the
* Free Software Foundation; either version 2, or (at your option) any
* later version.
*
* This program is distributed in the hope that it will be useful, but
* WITHOUT ANY WARRANTY; without even the implied warranty of
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
* General Public License for more details.
*
* You should have received a copy of the GNU General Public License along
* with this program; if not, write to the Free Software Foundation, Inc.,
* 675 Mass Ave, Cambridge, MA 02139, USA.
*/
#include <err.h>
#include <errno.h>
#include <getopt.h>
#include <sched.h>
#include <stdio.h>
#include <stdlib.h>
#include <unistd.h>
#include "nls.h"
#ifndef CLONE_NEWSNS
# define CLONE_NEWNS 0x00020000
#endif
#ifndef CLONE_NEWUTS
# define CLONE_NEWUTS 0x04000000
#endif
#ifndef CLONE_NEWIPC
# define CLONE_NEWIPC 0x08000000
#endif
#ifndef CLONE_NEWNET
# define CLONE_NEWNET 0x40000000
#endif
#ifndef HAVE_UNSHARE
# include <sys/syscall.h>
static int unshare(int flags)
{
return syscall(SYS_unshare, flags);
}
#endif
static void usage(int status)
{
FILE *out = status == EXIT_SUCCESS ? stdout : stderr;
fprintf(out, _("Usage: %s [options] <program> [args...]\n"),
program_invocation_short_name);
fputs(_("Run program with some namespaces unshared from parent\n\n"
" -h, --help usage information (this)\n"
" -m, --mount unshare mounts namespace\n"
" -u, --uts unshare UTS namespace (hostname etc)\n"
" -i, --ipc unshare System V IPC namespace\n"
" -n, --net unshare network namespace\n"), out);
fprintf(out, _("\nFor more information see unshare(1).\n"));
exit(status);
}
int main(int argc, char *argv[])
{
struct option longopts[] = {
{ "help", no_argument, 0, 'h' },
{ "mount", no_argument, 0, 'm' },
{ "uts", no_argument, 0, 'u' },
{ "ipc", no_argument, 0, 'i' },
{ "net", no_argument, 0, 'n' },
{ NULL, 0, 0, 0 }
};
int unshare_flags = 0;
int c;
setlocale(LC_MESSAGES, "");
bindtextdomain(PACKAGE, LOCALEDIR);
textdomain(PACKAGE);
while((c = getopt_long(argc, argv, "hmuin", longopts, NULL)) != -1) {
switch(c) {
case 'h':
usage(EXIT_SUCCESS);
case 'm':
unshare_flags |= CLONE_NEWNS;
break;
case 'u':
unshare_flags |= CLONE_NEWUTS;
break;
case 'i':
unshare_flags |= CLONE_NEWIPC;
break;
case 'n':
unshare_flags |= CLONE_NEWNET;
break;
default:
usage(EXIT_FAILURE);
}
}
if(optind >= argc)
usage(EXIT_FAILURE);
if(-1 == unshare(unshare_flags))
err(EXIT_FAILURE, _("unshare failed"));
/* drop potential root euid/egid if we had been setuid'd */
if (setgid(getgid()) < 0)
err(EXIT_FAILURE, _("cannot set group id"));
if (setuid(getuid()) < 0)
err(EXIT_FAILURE, _("cannot set user id"));
execvp(argv[optind], argv + optind);
err(EXIT_FAILURE, _("exec %s failed"), argv[optind]);
}
|