Samuel Ortiz
1fc0b94fcd
cargo: Move to crates.io vm-memory 0.4.0
...
vm-memory 0.4.0 now contains all our fixes.
Signed-off-by: Samuel Ortiz <sameo@linux.intel.com >
2020-11-23 10:55:13 +01:00
dependabot-preview[bot]
f7c42dc7d2
build(deps): bump vmm-sys-util from 0.6.1 to 0.7.0
...
Bumps [vmm-sys-util](https://github.com/rust-vmm/vmm-sys-util ) from 0.6.1 to 0.7.0.
- [Release notes](https://github.com/rust-vmm/vmm-sys-util/releases )
- [Changelog](https://github.com/rust-vmm/vmm-sys-util/blob/master/CHANGELOG.md )
- [Commits](https://github.com/rust-vmm/vmm-sys-util/compare/v0.6.1...v0.7.0 )
Signed-off-by: dependabot-preview[bot] <support@dependabot.com >
2020-11-13 15:55:05 +00:00
dependabot-preview[bot]
50e0423304
build(deps): bump futures from 0.3.7 to 0.3.8
...
Bumps [futures](https://github.com/rust-lang/futures-rs ) from 0.3.7 to 0.3.8.
- [Release notes](https://github.com/rust-lang/futures-rs/releases )
- [Changelog](https://github.com/rust-lang/futures-rs/blob/master/CHANGELOG.md )
- [Commits](https://github.com/rust-lang/futures-rs/compare/0.3.7...0.3.8 )
Signed-off-by: dependabot-preview[bot] <support@dependabot.com >
2020-11-09 21:50:00 +00:00
dependabot-preview[bot]
f0d0d8ccaf
build(deps): bump libc from 0.2.79 to 0.2.80
...
Bumps [libc](https://github.com/rust-lang/libc ) from 0.2.79 to 0.2.80.
- [Release notes](https://github.com/rust-lang/libc/releases )
- [Commits](https://github.com/rust-lang/libc/compare/0.2.79...0.2.80 )
Signed-off-by: dependabot-preview[bot] <support@dependabot.com >
2020-10-26 09:31:03 +00:00
dependabot-preview[bot]
499fbd0367
build(deps): bump futures from 0.3.6 to 0.3.7
...
Bumps [futures](https://github.com/rust-lang/futures-rs ) from 0.3.6 to 0.3.7.
- [Release notes](https://github.com/rust-lang/futures-rs/releases )
- [Changelog](https://github.com/rust-lang/futures-rs/blob/master/CHANGELOG.md )
- [Commits](https://github.com/rust-lang/futures-rs/compare/0.3.6...0.3.7 )
Signed-off-by: dependabot-preview[bot] <support@dependabot.com >
2020-10-24 00:08:41 +00:00
Rob Bradford
e9880ab0d1
vhost_user_fs: seccomp: Propagate error correctly
...
Signed-off-by: Rob Bradford <robert.bradford@intel.com >
2020-10-19 21:53:38 -07:00
Rob Bradford
02621c6150
vhost_user_fs: sandbox: Fix clippy errors
...
Signed-off-by: Rob Bradford <robert.bradford@intel.com >
2020-10-19 21:53:38 -07:00
dependabot-preview[bot]
e553c053af
build(deps): bump futures from 0.3.5 to 0.3.6
...
Bumps [futures](https://github.com/rust-lang/futures-rs ) from 0.3.5 to 0.3.6.
- [Release notes](https://github.com/rust-lang/futures-rs/releases )
- [Changelog](https://github.com/rust-lang/futures-rs/blob/master/CHANGELOG.md )
- [Commits](https://github.com/rust-lang/futures-rs/commits )
Signed-off-by: dependabot-preview[bot] <support@dependabot.com >
2020-10-06 06:34:18 +00:00
dependabot-preview[bot]
c2cc26fc82
build(deps): bump libc from 0.2.78 to 0.2.79
...
Bumps [libc](https://github.com/rust-lang/libc ) from 0.2.78 to 0.2.79.
- [Release notes](https://github.com/rust-lang/libc/releases )
- [Commits](https://github.com/rust-lang/libc/compare/0.2.78...0.2.79 )
Signed-off-by: dependabot-preview[bot] <support@dependabot.com >
2020-10-05 07:02:05 +00:00
Rob Bradford
6a9934d933
build: Fix vm-memory bump build error
...
A new version of vm-memory was released upstream which resulted in some
components pulling in that new version. Update the version number used
to point to the latest version but continue to use our patched version
due to the fix for #1258
Signed-off-by: Rob Bradford <robert.bradford@intel.com >
2020-10-02 16:38:02 +01:00
dependabot-preview[bot]
76c3230e08
build(deps): bump libc from 0.2.77 to 0.2.78
...
Bumps [libc](https://github.com/rust-lang/libc ) from 0.2.77 to 0.2.78.
- [Release notes](https://github.com/rust-lang/libc/releases )
- [Commits](https://github.com/rust-lang/libc/compare/0.2.77...0.2.78 )
Signed-off-by: dependabot-preview[bot] <support@dependabot.com >
2020-10-01 05:40:02 +00:00
Josh Soref
5c3f4dbe6f
ch: Fix various misspelled words
...
Misspellings were identified by https://github.com/marketplace/actions/check-spelling
* Initial corrections suggested by Google Sheets
* Additional corrections by Google Chrome auto-suggest
* Some manual corrections
Signed-off-by: Josh Soref <jsoref@users.noreply.github.com >
2020-09-23 08:59:31 +01:00
Rob Bradford
bd463324f3
build: Move to rust-vmm vhost crate
...
There is no need to point at our forked version any longer.
Signed-off-by: Rob Bradford <robert.bradford@intel.com >
2020-09-11 13:43:57 +02:00
dependabot-preview[bot]
f24a12913a
build(deps): bump libc from 0.2.76 to 0.2.77
...
Bumps [libc](https://github.com/rust-lang/libc ) from 0.2.76 to 0.2.77.
- [Release notes](https://github.com/rust-lang/libc/releases )
- [Commits](https://github.com/rust-lang/libc/compare/0.2.76...0.2.77 )
Signed-off-by: dependabot-preview[bot] <support@dependabot.com >
2020-09-10 06:45:09 +00:00
dependabot-preview[bot]
57ff608be9
build(deps): bump libc from 0.2.74 to 0.2.76
...
Bumps [libc](https://github.com/rust-lang/libc ) from 0.2.74 to 0.2.76.
- [Release notes](https://github.com/rust-lang/libc/releases )
- [Commits](https://github.com/rust-lang/libc/compare/0.2.74...0.2.76 )
Signed-off-by: dependabot-preview[bot] <support@dependabot.com >
2020-08-21 07:08:35 +00:00
dependabot-preview[bot]
ebe61de0d1
build(deps): bump clap from 2.33.2 to 2.33.3
...
Bumps [clap](https://github.com/clap-rs/clap ) from 2.33.2 to 2.33.3.
- [Release notes](https://github.com/clap-rs/clap/releases )
- [Changelog](https://github.com/clap-rs/clap/blob/master/CHANGELOG.md )
- [Commits](https://github.com/clap-rs/clap/commits )
Signed-off-by: dependabot-preview[bot] <support@dependabot.com >
2020-08-14 06:18:55 +00:00
dependabot-preview[bot]
7529a9ac05
build(deps): bump seccomp from v0.21.2 to v0.22.0
...
Bumps [seccomp](https://github.com/firecracker-microvm/firecracker ) from v0.21.2 to v0.22.0.
- [Release notes](https://github.com/firecracker-microvm/firecracker/releases )
- [Changelog](cc5387637c/CHANGELOG.md )
- [Commits](a06d358b2e...cc5387637c )
Signed-off-by: dependabot-preview[bot] <support@dependabot.com >
2020-08-06 07:25:30 +00:00
dependabot-preview[bot]
8e8ec74b2a
build(deps): bump clap from 2.33.1 to 2.33.2
...
Bumps [clap](https://github.com/clap-rs/clap ) from 2.33.1 to 2.33.2.
- [Release notes](https://github.com/clap-rs/clap/releases )
- [Changelog](https://github.com/clap-rs/clap/blob/master/CHANGELOG.md )
- [Commits](https://github.com/clap-rs/clap/commits )
Signed-off-by: dependabot-preview[bot] <support@dependabot.com >
2020-08-05 20:36:12 +00:00
dependabot-preview[bot]
ec9de259ba
build(deps): bump seccomp from v0.21.1 to v0.21.2
...
Bumps [seccomp](https://github.com/firecracker-microvm/firecracker ) from v0.21.1 to v0.21.2.
- [Release notes](https://github.com/firecracker-microvm/firecracker/releases )
- [Changelog](a06d358b2e/CHANGELOG.md )
- [Commits](047a379eb0...a06d358b2e )
Signed-off-by: dependabot-preview[bot] <support@dependabot.com >
2020-08-05 07:34:44 +00:00
Ricardo Koller
358b3c0b89
Dummy change to start the tests
...
Signed-off-by: Ricardo Koller <ricarkol@gmail.com >
2020-08-05 08:38:58 +02:00
Ricardo Koller
7589f1b3bf
vhost_user_fs: increase RLIMIT_NOFILE
...
Increase the number of open files limit for the sandboxed process to the
maximum allowed in the system. The maximum is obtained by reading the
/proc/sys/fs/nr_open sysctl file, and the setting is done using the setrlimit
syscall. Failure to read or parse the nr_open file, or to set the rlimit
results in a panic.
Signed-off-by: Ricardo Koller <ricarkol@gmail.com >
2020-08-05 08:38:58 +02:00
dependabot-preview[bot]
12c5b7668a
build(deps): bump libc from 0.2.73 to 0.2.74
...
Bumps [libc](https://github.com/rust-lang/libc ) from 0.2.73 to 0.2.74.
- [Release notes](https://github.com/rust-lang/libc/releases )
- [Commits](https://github.com/rust-lang/libc/compare/0.2.73...0.2.74 )
Signed-off-by: dependabot-preview[bot] <support@dependabot.com >
2020-07-28 20:46:37 +00:00
dependabot-preview[bot]
12b37ef13b
build(deps): bump libc from 0.2.72 to 0.2.73
...
Bumps [libc](https://github.com/rust-lang/libc ) from 0.2.72 to 0.2.73.
- [Release notes](https://github.com/rust-lang/libc/releases )
- [Commits](https://github.com/rust-lang/libc/compare/0.2.72...0.2.73 )
Signed-off-by: dependabot-preview[bot] <support@dependabot.com >
2020-07-20 05:15:24 +00:00
dependabot-preview[bot]
cc57467d10
build(deps): bump log from 0.4.8 to 0.4.11
...
Bumps [log](https://github.com/rust-lang/log ) from 0.4.8 to 0.4.11.
- [Release notes](https://github.com/rust-lang/log/releases )
- [Changelog](https://github.com/rust-lang/log/blob/master/CHANGELOG.md )
- [Commits](https://github.com/rust-lang/log/compare/0.4.8...0.4.11 )
Signed-off-by: dependabot-preview[bot] <support@dependabot.com >
2020-07-16 05:33:44 +00:00
dependabot-preview[bot]
861337cc6f
build(deps): bump libc from 0.2.71 to 0.2.72
...
Bumps [libc](https://github.com/rust-lang/libc ) from 0.2.71 to 0.2.72.
- [Release notes](https://github.com/rust-lang/libc/releases )
- [Commits](https://github.com/rust-lang/libc/compare/0.2.71...0.2.72 )
Signed-off-by: dependabot-preview[bot] <support@dependabot.com >
2020-07-08 05:11:25 +00:00
Rob Bradford
d6a05ceabb
vhost_user_fs: Move binary into vhost_user_fs crate
...
The binary is still built in the same location but the source code and
the dependencies for it come from the vhost_user_fs crate itself.
The binary will be built with:
`cargo build --all --bin vhost_user_fs` or just `cargo build --all`
Signed-off-by: Rob Bradford <robert.bradford@intel.com >
2020-07-06 10:56:10 +02:00
Rob Bradford
2a6eb31d5b
vm-virtio, virtio-devices: Split device implementation from virt queues
...
Split the generic virtio code (queues and device type) from the
VirtioDevice trait, transport and device implementations.
This also simplifies the feature handling in vhost_user_backend as the
vm-virtio crate is no longer has any features.
Signed-off-by: Rob Bradford <robert.bradford@intel.com >
2020-07-02 17:09:28 +01:00
Dr. David Alan Gilbert
0583ce921b
vhost_user_fs: Allow fchmod in seccomp
...
This corresponds to QEMU's 63659fe74e76f5c52854 commit.
the setattr code uses both fchmod and fchmodat in different cases,
however we only had fchmodat in the whitelist.
Signed-off-by: Dr. David Alan Gilbert <dgilbert@redhat.com >
2020-06-24 21:56:58 +01:00
dependabot-preview[bot]
aac87196d6
build(deps): bump vm-memory from 0.2.0 to 0.2.1
...
Bumps [vm-memory](https://github.com/rust-vmm/vm-memory ) from 0.2.0 to 0.2.1.
- [Release notes](https://github.com/rust-vmm/vm-memory/releases )
- [Changelog](https://github.com/rust-vmm/vm-memory/blob/v0.2.1/CHANGELOG.md )
- [Commits](https://github.com/rust-vmm/vm-memory/compare/v0.2.0...v0.2.1 )
Signed-off-by: dependabot-preview[bot] <support@dependabot.com >
2020-05-28 17:06:48 +01:00
Rob Bradford
c31ad72ee9
build: Address issues found by 1.43.0 clippy
...
These are mostly due to use of "bare use" statements and unnecessary vector
creation.
Signed-off-by: Rob Bradford <robert.bradford@intel.com >
2020-05-27 19:32:12 +02:00
dependabot-preview[bot]
a4bb96d45c
build(deps): bump libc from 0.2.70 to 0.2.71
...
Bumps [libc](https://github.com/rust-lang/libc ) from 0.2.70 to 0.2.71.
- [Release notes](https://github.com/rust-lang/libc/releases )
- [Commits](https://github.com/rust-lang/libc/compare/0.2.70...0.2.71 )
Signed-off-by: dependabot-preview[bot] <support@dependabot.com >
2020-05-27 09:02:13 +02:00
Michael Zhao
1befae872d
build: Fixed build errors and warnings on AArch64
...
This is a preparing commit to build and test CH on AArch64. All building
issues were fixed, but no functionality was introduced.
For X86, the logic of code was not changed at all.
For ARM, the architecture specific part is still empty. And we applied
some tricks to workaround lint warnings. But such code will be replaced
later by other commits with real functionality.
Signed-off-by: Michael Zhao <michael.zhao@arm.com >
2020-05-21 11:56:26 +01:00
Rob Bradford
5a55fc0737
vhost_user_fs: Fix seccomp filter for musl
...
Add missing syscall used by the musl build.
TEST=scripts/dev_cli.sh tests --libc musl --integration -- vhost_user_fs_daemon
Signed-off-by: Rob Bradford <robert.bradford@intel.com >
2020-05-15 16:33:48 +02:00
Dr. David Alan Gilbert
4120a7dee9
vhost_user_fs: Add seccomp
...
Implement seccomp; we use one filter for all threads.
The syscall list comes from the C daemon with syscalls added
as I hit them.
The default behaviour is to kill the process, this normally gets
audit logged.
--seccomp none disables seccomp
log Just logs violations but doesn't stop it
trap causes a signal to be be sent that can be trapped.
If you suspect you're hitting a seccomp action then you can
check the audit log; you could also switch to running with 'log'
to collect a bunch of calls to report.
To see where the syscalls are coming from use 'trap' with a debugger
or coredump to backtrace it.
This can be improved for some syscalls to restrict the parameters
to some syscalls to make them more restrictive.
Signed-off-by: Dr. David Alan Gilbert <dgilbert@redhat.com >
2020-05-14 18:56:19 +02:00
Sergio Lopez
6aab0a5458
vhost_user_fs: Implement support for optional sandboxing
...
Implement support for setting up a sandbox for running the
service. The technique for this has been borrowed from virtiofsd, and
consists on switching to new PID, mount and network namespaces, and
then switching root to the directory to be shared.
Future patches will implement additional hardening features like
dropping capabilities and seccomp filters.
Signed-off-by: Sergio Lopez <slp@redhat.com >
2020-05-14 17:16:23 +02:00
Sergio Lopez
fa844865a5
vhost_user_fs: Allow callers to provide a fd for /proc/self/fd
...
Allow callers to provide a file descriptor for /proc/self/fd. This is
useful for sandboxing, as we may be running in a namespace that
doesn't have access to /proc.
Signed-off-by: Sergio Lopez <slp@redhat.com >
2020-05-14 17:16:23 +02:00
Sergio Lopez
831cff3fee
vhost_user_fs: Use a fd for /proc/self/fd instead of /proc
...
Open a file descriptor to /proc/self/fd instead of /proc. We aren't
using any other entries from that directory, and doing this allows us
to keep working even if /proc is no longer present in our
namespace (useful for sandboxing).
Signed-off-by: Sergio Lopez <slp@redhat.com >
2020-05-14 17:16:23 +02:00
dependabot-preview[bot]
2991fd2a48
build(deps): bump libc from 0.2.69 to 0.2.70
...
Bumps [libc](https://github.com/rust-lang/libc ) from 0.2.69 to 0.2.70.
- [Release notes](https://github.com/rust-lang/libc/releases )
- [Commits](https://github.com/rust-lang/libc/compare/0.2.69...0.2.70 )
Signed-off-by: dependabot-preview[bot] <support@dependabot.com >
2020-05-12 20:26:43 +02:00
Samuel Ortiz
86fcd19b8a
build: Initial musl support
...
Fix all build failures and add musl to the gihub workflows.
Signed-off-by: Samuel Ortiz <sameo@linux.intel.com >
2020-04-29 17:57:01 +01:00
Sergio Lopez
b7faf4fdc1
vhost_user_fs: Add the WRITE_KILL_PRIV write flag.
...
Add the WRITE_KILL_PRIV write flag, corresponding to
FUSE_WRITE_KILL_PRIV introduced in 7.31, and use to only remove the
setuid and setgid bits (by switching credentials) conditionally.
Signed-off-by: Sergio Lopez <slp@redhat.com >
2020-04-17 15:42:40 +01:00
Sergio Lopez
0870028fde
vhost_user_fs: Add the IOCTL_COMPAT_32 flag
...
Add the IOCTL_COMPAT_32 flag, corresponding to FUSE_IOCTL_COMPAT_32
introduced in FUSE 7.30.
Signed-off-by: Sergio Lopez <slp@redhat.com >
2020-04-17 15:42:40 +01:00
Sergio Lopez
592cfbafb3
vhost_user_fs: Add the EXPLICIT_INVAL_DATA capability flag
...
Add EXPLICIT_INVAL_DATA capability flag, corresponding to
FUSE_EXPLICIT_INVAL_DATA introduced in FUSE 7.30.
Signed-off-by: Sergio Lopez <slp@redhat.com >
2020-04-17 15:42:40 +01:00
Sergio Lopez
621ea837fa
vhost_user_fs: Add the ZERO_MESSAGE_OPENDIR capability flag
...
Add ZERO_MESSAGE_OPENDIR capability flag, corresponding to
FUSE_NO_OPENDIR_SUPPORT introduced in FUSE 7.29.
Signed-off-by: Sergio Lopez <slp@redhat.com >
2020-04-17 15:42:40 +01:00
Sergio Lopez
a2830da7c0
vhost_user_fs: Add the CACHE_SYMLINKS flag
...
Add the CACHE_SYMLINKS flag, corresponding to FUSE_CACHE_SYMLINKS
introduced in FUSE 7.28.
Signed-off-by: Sergio Lopez <slp@redhat.com >
2020-04-17 15:42:40 +01:00
Sergio Lopez
926a414b90
vhost_user_fs: Add support for MAX_PAGES
...
Add support for MAX_PAGES, corresonding to FUSE_MAX_PAGES introduced
in FUSE 7.28.
This allows us to negotiate with the kernel the maximum number of
pages that we support to transfer in a single request.
Signed-off-by: Sergio Lopez <slp@redhat.com >
2020-04-17 15:42:40 +01:00
Sergio Lopez
747f31d82c
vhost_user_fs: Add the ABORT_ERROR flag
...
Add the ABORT_ERROR flag, corresponding to FUSE_ABORT_ERROR,
introduced in FUSE 7.27.
Signed-off-by: Sergio Lopez <slp@redhat.com >
2020-04-17 15:42:40 +01:00
Sergio Lopez
5eb903a509
vhost_user_fs: Add support for FOPEN_CACHE_DIR
...
Add support for FOPEN_CACHE_DIR, a flag that allows us to tell the
guest that it's safe to cache a directory, introduced in FUSE 7.28.
Signed-off-by: Sergio Lopez <slp@redhat.com >
2020-04-17 15:42:40 +01:00
Sergio Lopez
97e2d5d266
vhost_user_fs: Add support for CopyFileRange
...
Add support for the CopyFileRange request, introduced in FUSE 7.28.
Signed-off-by: Sergio Lopez <slp@redhat.com >
2020-04-17 15:42:40 +01:00
dependabot-preview[bot]
886c0f9093
build(deps): bump libc from 0.2.68 to 0.2.69
...
Bumps [libc](https://github.com/rust-lang/libc ) from 0.2.68 to 0.2.69.
- [Release notes](https://github.com/rust-lang/libc/releases )
- [Commits](https://github.com/rust-lang/libc/compare/0.2.68...0.2.69 )
Signed-off-by: dependabot-preview[bot] <support@dependabot.com >
2020-04-14 09:27:04 +01:00
Yang Zhong
183529d024
vmm: Cleanup warning from build
...
Remove unnecessary parentheses from code and this will cleanup
the warning from cargo build.
Signed-off-by: Yang Zhong <yang.zhong@intel.com >
2020-04-07 09:45:31 +02:00