ABC-22: Plugin sandboxing for linux/amd64 (#8068)

* plugin sandboxing

* remove unused type

* better symlink handling, better remounting, better test, whitespace
fixes, and comment on the remounting

* fix test compile error

* big simplification for getting mount flags

* mask statfs flags to the ones we're interested in
Этот коммит содержится в:
Chris
2018-01-15 11:21:06 -06:00
коммит произвёл Christopher Speller
родитель 7e5ce97668
Коммит f5c8a71698
20 изменённых файлов: 1716 добавлений и 194 удалений

33
plugin/rpcplugin/sandbox/supervisor.go Обычный файл
Просмотреть файл

@@ -0,0 +1,33 @@
// Copyright (c) 2015-present Mattermost, Inc. All Rights Reserved.
// See License.txt for license information.
package sandbox
import (
"context"
"fmt"
"io"
"path/filepath"
"strings"
"github.com/mattermost/mattermost-server/model"
"github.com/mattermost/mattermost-server/plugin"
"github.com/mattermost/mattermost-server/plugin/rpcplugin"
)
func SupervisorProvider(bundle *model.BundleInfo) (plugin.Supervisor, error) {
return rpcplugin.SupervisorWithNewProcessFunc(bundle, func(ctx context.Context) (rpcplugin.Process, io.ReadWriteCloser, error) {
executable := filepath.Clean(filepath.Join(".", bundle.Manifest.Backend.Executable))
if strings.HasPrefix(executable, "..") {
return nil, nil, fmt.Errorf("invalid backend executable")
}
return NewProcess(ctx, &Configuration{
MountPoints: []*MountPoint{{
Source: bundle.Path,
Destination: "/plugin",
ReadOnly: true,
}},
WorkingDirectory: "/plugin",
}, filepath.Join("/plugin", executable))
})
}