mirror of
https://git.proxmox.com/git/mirror_lxc
synced 2025-07-27 12:28:27 +00:00
provide a script to set uid bit on cli
Some file systems do not support the file posix capabilities. The following script set the setuid bit root on the different cli. Signed-off-by: Daniel Lezcano <dlezcano@fr.ibm.com>
This commit is contained in:
parent
00dbc43e30
commit
7a82e9236d
@ -148,6 +148,7 @@ AC_CONFIG_FILES([
|
|||||||
src/lxc/lxc-netstat
|
src/lxc/lxc-netstat
|
||||||
src/lxc/lxc-checkconfig
|
src/lxc/lxc-checkconfig
|
||||||
src/lxc/lxc-setcap
|
src/lxc/lxc-setcap
|
||||||
|
src/lxc/lxc-setuid
|
||||||
src/lxc/lxc-version
|
src/lxc/lxc-version
|
||||||
src/lxc/lxc-create
|
src/lxc/lxc-create
|
||||||
src/lxc/lxc-destroy
|
src/lxc/lxc-destroy
|
||||||
|
@ -67,6 +67,7 @@ bin_SCRIPTS = \
|
|||||||
lxc-ls \
|
lxc-ls \
|
||||||
lxc-checkconfig \
|
lxc-checkconfig \
|
||||||
lxc-setcap \
|
lxc-setcap \
|
||||||
|
lxc-setuid \
|
||||||
lxc-version \
|
lxc-version \
|
||||||
lxc-create \
|
lxc-create \
|
||||||
lxc-destroy
|
lxc-destroy
|
||||||
|
104
src/lxc/lxc-setuid.in
Normal file
104
src/lxc/lxc-setuid.in
Normal file
@ -0,0 +1,104 @@
|
|||||||
|
#!/bin/bash
|
||||||
|
|
||||||
|
#
|
||||||
|
# lxc: linux Container library
|
||||||
|
|
||||||
|
# Authors:
|
||||||
|
# Daniel Lezcano <daniel.lezcano@free.fr>
|
||||||
|
|
||||||
|
# This library is free software; you can redistribute it and/or
|
||||||
|
# modify it under the terms of the GNU Lesser General Public
|
||||||
|
# License as published by the Free Software Foundation; either
|
||||||
|
# version 2.1 of the License, or (at your option) any later version.
|
||||||
|
|
||||||
|
# This library is distributed in the hope that it will be useful,
|
||||||
|
# but WITHOUT ANY WARRANTY; without even the implied warranty of
|
||||||
|
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
|
||||||
|
# Lesser General Public License for more details.
|
||||||
|
|
||||||
|
# You should have received a copy of the GNU Lesser General Public
|
||||||
|
# License along with this library; if not, write to the Free Software
|
||||||
|
# Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA
|
||||||
|
|
||||||
|
#
|
||||||
|
# This script allows to set or remove the setuid execution bit on the lxc tools.
|
||||||
|
# When the capabilities are set, a non root user can manage the containers.
|
||||||
|
#
|
||||||
|
|
||||||
|
usage()
|
||||||
|
{
|
||||||
|
echo "lxc-setuid [-d] : set or remove setuid on the lxc tools"
|
||||||
|
}
|
||||||
|
|
||||||
|
setuid()
|
||||||
|
{
|
||||||
|
if [ "$1" = "-r" ]; then
|
||||||
|
chmod -s $2
|
||||||
|
else
|
||||||
|
chmod +s $1
|
||||||
|
fi
|
||||||
|
}
|
||||||
|
|
||||||
|
lxc_setuid()
|
||||||
|
{
|
||||||
|
setuid @BINDIR@/lxc-execute
|
||||||
|
setuid @BINDIR@/lxc-restart
|
||||||
|
setuid @BINDIR@/lxc-unshare
|
||||||
|
setuid @BINDIR@/lxc-netstat
|
||||||
|
setuid @BINDIR@/lxc-checkpoint
|
||||||
|
setuid @LXCINITDIR@/lxc-init
|
||||||
|
|
||||||
|
test -e @LXCPATH@ || mkdir -p @LXCPATH@
|
||||||
|
chmod 0777 @LXCPATH@
|
||||||
|
}
|
||||||
|
|
||||||
|
lxc_dropuid()
|
||||||
|
{
|
||||||
|
setuid -r @BINDIR@/lxc-execute
|
||||||
|
setuid -r @BINDIR@/lxc-restart
|
||||||
|
setuid -r @BINDIR@/lxc-unshare
|
||||||
|
setuid -r @BINDIR@/lxc-netstat
|
||||||
|
setuid -r @BINDIR@/lxc-checkpoint
|
||||||
|
setuid -r @LXCINITDIR@/lxc-init
|
||||||
|
chmod 0755 @LXCPATH@
|
||||||
|
}
|
||||||
|
|
||||||
|
if [ "$(id -u)" != "0" ]; then
|
||||||
|
echo "You have to be root to run this script"
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
|
||||||
|
if [ $? != 0 ]; then
|
||||||
|
usage
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
set -- $(getopt dh $*)
|
||||||
|
|
||||||
|
for i in $*; do
|
||||||
|
case "$1" in
|
||||||
|
-d)
|
||||||
|
LXC_DROP_CAPS="yes"
|
||||||
|
shift
|
||||||
|
;;
|
||||||
|
-h)
|
||||||
|
usage
|
||||||
|
exit 0
|
||||||
|
;;
|
||||||
|
--)
|
||||||
|
shift
|
||||||
|
break
|
||||||
|
;;
|
||||||
|
*)
|
||||||
|
usage
|
||||||
|
exit 1
|
||||||
|
;;
|
||||||
|
esac
|
||||||
|
done;
|
||||||
|
|
||||||
|
if [ -z "$LXC_DROP_CAPS" ]; then
|
||||||
|
lxc_setuid
|
||||||
|
else
|
||||||
|
lxc_dropuid
|
||||||
|
fi
|
Loading…
Reference in New Issue
Block a user