25 lines
961 B
Bash
Executable File
25 lines
961 B
Bash
Executable File
#!/usr/bin/env bash
|
|
# netvm-enter.sh <node> <uid> <gid> <home> -- <cmd> [args...]
|
|
# Enter the node's netns, bind a working resolv.conf (host uses the
|
|
# systemd-resolved stub 127.0.0.53, unreachable in the netns), drop
|
|
# privileges, exec the command. Run as root (sudo -n via the allowlist).
|
|
set -euo pipefail
|
|
SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd)"
|
|
. "$SCRIPT_DIR/netvm-names.sh"
|
|
netvm_names "$1"; TUID="$2"; TGID="$3"; THOME="$4"; shift 4
|
|
[ "${1:-}" = "--" ]; shift
|
|
RESOLV=/etc/netvm/resolv-warp.conf
|
|
[ -f "$RESOLV" ] || echo "nameserver 1.1.1.1" > "$RESOLV"
|
|
|
|
EXEC_CMD=(ip netns exec "$NETNS" env \
|
|
NETVM_RESOLV="$RESOLV" NETVM_UID="$TUID" NETVM_GID="$TGID" NETVM_HOME="$THOME" \
|
|
unshare --mount "$SCRIPT_DIR/netvm-enter-inner.sh" "$@")
|
|
|
|
if command -v systemd-run >/dev/null 2>&1; then
|
|
UNIT_NAME="netvm-${NODE}-$RANDOM"
|
|
exec systemd-run --scope -p MemoryMax=2G -p CPUQuota=200% --unit="$UNIT_NAME" "${EXEC_CMD[@]}"
|
|
else
|
|
exec "${EXEC_CMD[@]}"
|
|
fi
|
|
|