selinux.go 2.0 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960
  1. package control
  2. import (
  3. "fmt"
  4. "syscall"
  5. "github.com/codegangsta/cli"
  6. "github.com/rancher/os/config"
  7. )
  8. func selinuxCommand() cli.Command {
  9. app := cli.Command{}
  10. app.Name = "selinux"
  11. app.Usage = "Launch SELinux tools container."
  12. app.Action = func(c *cli.Context) error {
  13. argv := []string{"system-docker", "run", "-it", "--privileged", "--rm",
  14. "--net", "host", "--pid", "host", "--ipc", "host",
  15. "-v", "/usr/bin/docker:/usr/bin/docker.dist:ro",
  16. "-v", "/usr/bin/ros:/usr/bin/dockerlaunch:ro",
  17. "-v", "/usr/bin/ros:/usr/bin/user-docker:ro",
  18. "-v", "/usr/bin/ros:/usr/bin/system-docker:ro",
  19. "-v", "/usr/bin/ros:/sbin/poweroff:ro",
  20. "-v", "/usr/bin/ros:/sbin/reboot:ro",
  21. "-v", "/usr/bin/ros:/sbin/halt:ro",
  22. "-v", "/usr/bin/ros:/sbin/shutdown:ro",
  23. "-v", "/usr/bin/ros:/usr/bin/respawn:ro",
  24. "-v", "/usr/bin/ros:/usr/bin/ros:ro",
  25. "-v", "/usr/bin/ros:/usr/bin/cloud-init:ro",
  26. "-v", "/usr/bin/ros:/usr/sbin/netconf:ro",
  27. "-v", "/usr/bin/ros:/usr/sbin/wait-for-network:ro",
  28. "-v", "/usr/bin/ros:/usr/sbin/wait-for-docker:ro",
  29. "-v", "/var/lib/docker:/var/lib/docker",
  30. "-v", "/var/lib/rkt:/var/lib/rkt",
  31. "-v", "/dev:/host/dev",
  32. "-v", "/etc/docker:/etc/docker",
  33. "-v", "/etc/hosts:/etc/hosts",
  34. "-v", "/etc/resolv.conf:/etc/resolv.conf",
  35. "-v", "/etc/rkt:/etc/rkt",
  36. "-v", "/etc/ssl/certs/ca-certificates.crt:/etc/ssl/certs/ca-certificates.crt.rancher",
  37. "-v", "/lib/firmware:/lib/firmware",
  38. "-v", "/lib/modules:/lib/modules",
  39. "-v", "/run:/run",
  40. "-v", "/usr/share/ros:/usr/share/ros",
  41. "-v", "/var/lib/rancher/conf:/var/lib/rancher/conf",
  42. "-v", "/var/lib/rancher:/var/lib/rancher",
  43. "-v", "/var/log:/var/log",
  44. "-v", "/var/run:/var/run",
  45. "-v", "/home:/home",
  46. "-v", "/opt:/opt",
  47. "-v", "/etc/selinux:/etc/selinux",
  48. "-v", "/var/lib/selinux:/var/lib/selinux",
  49. "-v", "/usr/share/selinux:/usr/share/selinux",
  50. fmt.Sprintf("rancher/os-selinuxtools:%s", config.VERSION+config.SUFFIX), "bash"}
  51. syscall.Exec("/bin/system-docker", argv, []string{})
  52. return nil
  53. }
  54. return app
  55. }