mnexec: mount sysfs in each container
The sysfs filesystem is [tagged][1] with a set of namespaces when mounted, taken from the mounting process. Among other things, this controls which network devices will show up in /sys/class/net and /sys/class/net/bonding_masters. Without this change, mininet will not mount sysfs in a node. Attempting to configure a bond interface in a node will only affect the parent namespace. This change mounts a new sysfs filesystem in each node. To prevent this mount from affecting the parent namespace the mount namespace is also unshared. [1]: https://www.kernel.org/doc/Documentation/filesystems/sysfs-tagging.txt
This commit is contained in:
@@ -5,7 +5,7 @@
|
|||||||
*
|
*
|
||||||
* - closing all file descriptors except stdin/out/error
|
* - closing all file descriptors except stdin/out/error
|
||||||
* - detaching from a controlling tty using setsid
|
* - detaching from a controlling tty using setsid
|
||||||
* - running in a network namespace
|
* - running in network and mount namespaces
|
||||||
* - printing out the pid of a process so we can identify it later
|
* - printing out the pid of a process so we can identify it later
|
||||||
* - attaching to a namespace and cgroup
|
* - attaching to a namespace and cgroup
|
||||||
* - setting RT scheduling
|
* - setting RT scheduling
|
||||||
@@ -23,6 +23,7 @@
|
|||||||
#include <stdlib.h>
|
#include <stdlib.h>
|
||||||
#include <sched.h>
|
#include <sched.h>
|
||||||
#include <ctype.h>
|
#include <ctype.h>
|
||||||
|
#include <sys/mount.h>
|
||||||
|
|
||||||
#if !defined(VERSION)
|
#if !defined(VERSION)
|
||||||
#define VERSION "(devel)"
|
#define VERSION "(devel)"
|
||||||
@@ -35,9 +36,9 @@ void usage(char *name)
|
|||||||
"Options:\n"
|
"Options:\n"
|
||||||
" -c: close all file descriptors except stdin/out/error\n"
|
" -c: close all file descriptors except stdin/out/error\n"
|
||||||
" -d: detach from tty by calling setsid()\n"
|
" -d: detach from tty by calling setsid()\n"
|
||||||
" -n: run in new network namespace\n"
|
" -n: run in new network and mount namespaces\n"
|
||||||
" -p: print ^A + pid\n"
|
" -p: print ^A + pid\n"
|
||||||
" -a pid: attach to pid's network namespace\n"
|
" -a pid: attach to pid's network and mount namespaces\n"
|
||||||
" -g group: add to cgroup\n"
|
" -g group: add to cgroup\n"
|
||||||
" -r rtprio: run with SCHED_RR (usually requires -g)\n"
|
" -r rtprio: run with SCHED_RR (usually requires -g)\n"
|
||||||
" -v: print version\n",
|
" -v: print version\n",
|
||||||
@@ -122,11 +123,16 @@ int main(int argc, char *argv[])
|
|||||||
setsid();
|
setsid();
|
||||||
break;
|
break;
|
||||||
case 'n':
|
case 'n':
|
||||||
/* run in network namespace */
|
/* run in network and mount namespaces */
|
||||||
if (unshare(CLONE_NEWNET) == -1) {
|
if (unshare(CLONE_NEWNET|CLONE_NEWNS) == -1) {
|
||||||
perror("unshare");
|
perror("unshare");
|
||||||
return 1;
|
return 1;
|
||||||
}
|
}
|
||||||
|
/* mount sysfs to pick up the new network namespace */
|
||||||
|
if (mount("sysfs", "/sys", "sysfs", MS_MGC_VAL, NULL) == -1) {
|
||||||
|
perror("mount");
|
||||||
|
return 1;
|
||||||
|
}
|
||||||
break;
|
break;
|
||||||
case 'p':
|
case 'p':
|
||||||
/* print pid */
|
/* print pid */
|
||||||
|
|||||||
Reference in New Issue
Block a user