summaryrefslogtreecommitdiffstats
path: root/src/runner/runc/run.rs
blob: 09bd875fed73dde83f6f3b95fb52b4cefa4c7e16 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
use std::{
	fs::{DirBuilder, File},
	io,
	path::{Path, PathBuf},
	process,
};

use nix::{
	mount::{self, MsFlags},
	sched::{self, CloneFlags},
	unistd,
};
use serde::{Deserialize, Serialize};

use crate::{
	types::*,
	unshare,
	util::{self, ToIOResult},
};

use super::spec;

#[derive(Debug, Deserialize, Serialize)]
pub enum Error {
	Code(i32),
	String(String),
}

impl From<io::Error> for Error {
	fn from(error: io::Error) -> Self {
		match error.raw_os_error() {
			Some(code) => Error::Code(code),
			None => Error::String(error.to_string()),
		}
	}
}

impl From<Error> for io::Error {
	fn from(error: Error) -> Self {
		match error {
			Error::Code(code) => io::Error::from_raw_os_error(code),
			Error::String(string) => io::Error::new(io::ErrorKind::Other, string),
		}
	}
}

fn init_task() -> Result<(), Error> {
	sched::unshare(CloneFlags::CLONE_NEWNS).to_io_result()?;

	mount::mount::<_, _, _, str>(
		Some("runc"),
		"build/tmp/runc",
		Some("tmpfs"),
		MsFlags::empty(),
		None,
	)
	.to_io_result()?;

	let workdir = "build/tmp/runc/workdir";
	DirBuilder::new().create(workdir)?;
	unistd::chown(
		workdir,
		Some(unistd::Uid::from_raw(unshare::BUILD_UID)),
		Some(unistd::Gid::from_raw(unshare::BUILD_GID)),
	)
	.to_io_result()?;

	Ok(())
}

fn output_filename(task: TaskRef) -> PathBuf {
	Path::new("build/state").join(format!("{}.tar", task))
}

fn collect_output(task: TaskRef, task_def: Task) -> Result<(), io::Error> {
	// Temporarily switch to the user running Rebel to get the right
	// owner for the tar files
	let file = {
		let _setegid = util::setegid(unistd::Gid::from_raw(unshare::BUILD_GID))?;
		let _seteuid = util::seteuid(unistd::Uid::from_raw(unshare::BUILD_UID))?;

		File::create(output_filename(task))?
	};

	util::tar::pack(file, "build/tmp/runc/workdir", task_def.output.iter())?.sync_all()
}

pub fn handle_task(task: TaskRef, task_def: Task) -> Result<(), Error> {
	init_task()?;

	spec::generate_spec(task_def.run.as_str())
		.save("build/tmp/runc/config.json")
		.expect("Saving runtime spec failed");

	let output = process::Command::new("runc")
		.arg("--root")
		.arg("build/tmp/runc/state")
		.arg("run")
		.arg("rebel")
		.current_dir("build/tmp/runc")
		.output()?;

	if !output.status.success() {
		println!(
			"{}:\n{}",
			task,
			String::from_utf8_lossy(output.stderr.as_slice()),
		);
		return Err(Error::String("Task failed".to_string()));
	}

	println!(
		"{}:\n{}",
		task,
		String::from_utf8_lossy(output.stdout.as_slice()),
	);

	collect_output(task, task_def)?;

	Ok(())
}