Commit Graph

3267 Commits

Author SHA1 Message Date
Fabricio Voznika 305f786e51 Adjust a few log messages
PiperOrigin-RevId: 311234146
2020-05-12 17:26:07 -07:00
gVisor bot 725afc6f25 Merge pull request #2678 from nybidari:iptables
PiperOrigin-RevId: 311203776
2020-05-12 14:37:00 -07:00
Nicolas Lacasse 7b691ab73c Don't allow rename across different gofer or tmpfs mounts.
Fixes #2651.

PiperOrigin-RevId: 311193661
2020-05-12 13:43:48 -07:00
gVisor bot a3f97a757a Merge pull request #2513 from amscanne:website-integrated
PiperOrigin-RevId: 311184385
2020-05-12 12:55:23 -07:00
gVisor bot 6a4466a46c Merge pull request #2671 from kevinGC:skip-output
PiperOrigin-RevId: 311181084
2020-05-12 12:39:03 -07:00
Jamie Liu 8dd1d5b75a Don't call kernel.Task.Block() from netstack.SocketOperations.Write().
kernel.Task.Block() requires that the caller is running on the task goroutine.
netstack.SocketOperations.Write() uses kernel.TaskFromContext() to call
kernel.Task.Block() even if it's not running on the task goroutine. Stop doing
that.

PiperOrigin-RevId: 311178335
2020-05-12 12:26:05 -07:00
Nayana Bidari 27b1f19cab iptables: support gid match for owner matching.
- Added support for matching gid owner and invert flag for uid
and gid.
$ iptables -A OUTPUT -p tcp -m owner --gid-owner root -j ACCEPT
$ iptables -A OUTPUT -p tcp -m owner ! --uid-owner root -j ACCEPT
$ iptables -A OUTPUT -p tcp -m owner ! --gid-owner root -j DROP

- Added tests for uid, gid and invert flags.
2020-05-12 12:20:47 -07:00
gVisor bot 06ded1c437 Merge pull request #2664 from lubinszARM:pr_sigfp
PiperOrigin-RevId: 311153824
2020-05-12 10:32:16 -07:00
Jamie Liu 94251aedb4 Internal change.
PiperOrigin-RevId: 311046755
2020-05-11 20:03:25 -07:00
Kevin Krakauer 87225fad2a iptables: check for truly unconditional rules
We weren't properly checking whether the inserted default rule was
unconditional.
2020-05-11 19:50:25 -07:00
Bin Lu 9bd9882b81 Add fpsimd support in sigreturn on Arm64
Signed-off-by: Bin Lu <bin.lu@arm.com>
2020-05-11 21:53:29 -04:00
Jamie Liu 15de8cc9e0 Add fsimpl/gofer.InternalFilesystemOptions.OpenSocketsByConnecting.
PiperOrigin-RevId: 311014995
2020-05-11 16:14:36 -07:00
gVisor bot 633e1b89bb Internal change.
PiperOrigin-RevId: 311011004
2020-05-11 15:54:08 -07:00
Bhasker Hariharan e838e7ab34 Automated rollback of changelist 310417191
PiperOrigin-RevId: 310963404
2020-05-11 12:09:06 -07:00
gVisor bot c5ab21b048 Internal change.
PiperOrigin-RevId: 310949277
2020-05-11 11:04:31 -07:00
Bhasker Hariharan 0cb9e1d021 Fix view.ToVectorisedView().
view.ToVectorisedView() now just returns an empty vectorised
view if the view is of zero length. Earlier it would return
a VectorisedView of zero length but with 1 empty view. This
has been a source of bugs as lower layers don't expect
zero length views in VectorisedViews.

VectorisedView.AppendView() now is a no-op if the view being
appended is of zero length.

Fixes #2658

PiperOrigin-RevId: 310942269
2020-05-11 10:35:28 -07:00
gVisor bot af2bc1c72a Internal change.
PiperOrigin-RevId: 310941717
2020-05-11 10:31:02 -07:00
Nicolas Lacasse c52195d258 Stop avoiding preadv2 and pwritev2, and add them to the filters.
Some code paths needed these syscalls anyways, so they should be included in
the filters. Given that we depend on these syscalls in some cases, there's no
real reason to avoid them any more.

PiperOrigin-RevId: 310829126
2020-05-10 17:52:20 -07:00
gVisor bot cfd30665c1 iptables - filter packets using outgoing interface.
Enables commands with -o (--out-interface) for iptables rules.
$ iptables -A OUTPUT -o eth0 -j ACCEPT

PiperOrigin-RevId: 310642286
2020-05-08 15:44:54 -07:00
Bhasker Hariharan e4d2d21f6b Add UDP send/recv packetimpact tests.
Fixes #2654

PiperOrigin-RevId: 310642216
2020-05-08 15:40:27 -07:00
Jamie Liu 21b71395a6 Pass flags to fsimpl/host.inode.open().
This has two effects: It makes flags passed to open("/proc/[pid]/fd/[hostfd]")
effective, and it prevents imported pipes/sockets/character devices from being
opened with O_NONBLOCK unconditionally (because the underlying host FD was set
to non-blocking in ImportFD()).

PiperOrigin-RevId: 310596062
2020-05-08 11:35:41 -07:00
Zeling Feng 5d7d5ed7d6 Send ACK to OTW SEQs/unacc ACKs in CLOSE_WAIT
This fixed the corresponding packetimpact test.

PiperOrigin-RevId: 310593470
2020-05-08 11:23:24 -07:00
gVisor bot c59e7b832c Merge pull request #2637 from avagin:make-vs-bazel
PiperOrigin-RevId: 310479788
2020-05-07 19:04:19 -07:00
Andrei Vagin 5d54ddcf03 make: exit with non-zero code if "bazel build" failed
Without this fix, make exits with zero code when bazel build failed:

$ make run TARGETS="--abra --kadabra"
ERROR: Unrecognized option: --abra
$ echo $?
0

Signed-off-by: Andrei Vagin <avagin@gmail.com>
2020-05-07 18:25:32 -07:00
Adin Scannell 5536073969 make: bazel docker container should clean itself up.
This change two does things:

1) Name the container based on the canonical directory path.

2) Allow the container to exit after bazel itself has exited.

The first is necessary to support multiple working directories,
while the second one allows these instances to clean up properly.

PiperOrigin-RevId: 310460748
2020-05-07 16:39:37 -07:00
Adin Scannell 7b4a913f36 Fix ARM64 build.
The common syscall definitions mean that ARM64-exclusive files need stubs in
the ARM64 build.

PiperOrigin-RevId: 310446698
2020-05-07 15:18:47 -07:00
Sam Balana 9242d3493d Capture range variable in parallel subtests
Only the last test was running before since the goroutines won't be executed
until after this loop. I added t.Log(test.name) and this is was the result:

TestListenNoAcceptNonUnicastV4/SourceUnspecified:    DestOtherMulticast
TestListenNoAcceptNonUnicastV4/DestUnspecified:      DestOtherMulticast
TestListenNoAcceptNonUnicastV4/DestOtherMulticast:   DestOtherMulticast
TestListenNoAcceptNonUnicastV4/SourceBroadcast:      DestOtherMulticast
TestListenNoAcceptNonUnicastV4/DestOurMulticast:     DestOtherMulticast
TestListenNoAcceptNonUnicastV4/DestBroadcast:        DestOtherMulticast
TestListenNoAcceptNonUnicastV4/SourceOtherMulticast: DestOtherMulticast
TestListenNoAcceptNonUnicastV4/SourceOurMulticast:   DestOtherMulticast

https://github.com/golang/go/wiki/TableDrivenTests#parallel-testing

PiperOrigin-RevId: 310440629
2020-05-07 14:46:51 -07:00
Jamie Liu 9115f26851 Allocate device numbers for VFS2 filesystems.
Updates #1197, #1198, #1672

PiperOrigin-RevId: 310432006
2020-05-07 14:01:53 -07:00
Adin Scannell 1f4087e7cd Fix tags used for determining file sets.
Updates #2569
Updates #2298

PiperOrigin-RevId: 310423629
2020-05-07 13:19:01 -07:00
Bhasker Hariharan 28b5565fdd Automated rollback of changelist 309339316
PiperOrigin-RevId: 310417191
2020-05-07 12:48:23 -07:00
Nicolas Lacasse d0b1d0233d Move pkg/sentry/vfs/{eventfd,timerfd} to new packages in pkg/sentry/fsimpl.
They don't depend on anything in VFS2, so they should be their own packages.

PiperOrigin-RevId: 310416807
2020-05-07 12:44:03 -07:00
gVisor bot 92cab8e2c3 Internal change.
PiperOrigin-RevId: 310409922
2020-05-07 12:10:02 -07:00
Nicolas Lacasse 26c60d7d5d Port signalfd to vfs2.
PiperOrigin-RevId: 310404113
2020-05-07 11:41:50 -07:00
Bhasker Hariharan 08f4846ebe Fix bugs in SACK recovery.
Every call to sender.NextSeg does not need to iterate from the
front of the writeList as in a given recovery episode we can cache
the last nextSeg returned. There cannot be a lower sequenced segment
that matches the next call to NextSeg as otherwise we would have
returned that instead in the previous call.

This fixes the issue of excessive CPU usage w/ large send buffers
where we spend a lot of time iterating from the front of the list on
every NextSeg invocation.

Further the following other bugs were also fixed:
  * Iteration of segments never sent in NextSeg() when looking for segments for
    retransmission that match step1/3/4 of the NextSeg algorithm
  * Correctly setting rescueRxt only if the rescue segment was actually sent.
  * Correctly initializing rescueRxt/highRxt when entering SACK recovery.
  * Correctly re-arming the timer only on retransmissions when SACK is in use
    and not for every segment being sent as it was being done before.
  * Copy over xmitTime and xmitCount on segment clone.
  * Move writeNext along when skipping over SACKED segments. This is required
    to prevent spurious retransmissions where we end up retransmitting data
    that was never lost.

PiperOrigin-RevId: 310387671
2020-05-07 10:26:00 -07:00
Dean Deng 16da7e790f Update privateunixsocket TODOs.
Synthetic sockets do not have the race condition issue in VFS2, and we will
get rid of privateunixsocket as well.

Fixes #1200.

PiperOrigin-RevId: 310386474
2020-05-07 10:20:48 -07:00
gVisor bot 553da2cdc8 Merge pull request #2639 from kevinGC:ipv4-frag-reassembly-test
PiperOrigin-RevId: 310380911
2020-05-07 09:58:30 -07:00
Dean Deng e0089a20e4 Remove outdated TODO for VFS2 AccessAt.
Fixes #1965.

PiperOrigin-RevId: 310380433
2020-05-07 09:53:52 -07:00
Kevin Krakauer 763b5ad596 Add basic incoming ipv4 fragment tests
Based on ipv6's TestReceiveIPv6Fragments.
2020-05-06 22:45:21 -07:00
gVisor bot feece24bf5 Merge pull request #2570 from lubinszARM:pr_clean
PiperOrigin-RevId: 310259686
2020-05-06 17:19:55 -07:00
Jamie Liu 7cd54c1f14 Remove vfs.FileDescriptionOptions.InvalidWrite.
Compare:
https://elixir.bootlin.com/linux/v5.6/source/fs/timerfd.c#L431
PiperOrigin-RevId: 310246908
2020-05-06 16:08:12 -07:00
Ghanan Gowripalan 485ca36adf Do not assume no DHCPv6 configurations
Do not assume that networks need any DHCPv6 configurations. Instead,
notify the NDP dispatcher in response to the first NDP RA's DHCPv6
flags, even if the flags indicate no DHCPv6 configurations are
available.

PiperOrigin-RevId: 310245068
2020-05-06 15:59:08 -07:00
Adin Scannell 5f3a256425 Add support for kramdown TOC. 2020-05-06 14:15:19 -07:00
Adin Scannell a10d5ed969 Add atom feed (at previous URL). 2020-05-06 14:15:19 -07:00
Adin Scannell 7de6fb18f9 Clean-up documentation. 2020-05-06 14:15:19 -07:00
Adin Scannell cf86ec5e40 Add powered by gVisor logo. 2020-05-06 14:15:19 -07:00
Adin Scannell d3c43401a7 Fixup link in CODE_OF_CONDUCT.md. 2020-05-06 14:15:18 -07:00
Adin Scannell 73d7024510 Fixup transitions for navbar. 2020-05-06 14:15:18 -07:00
Adin Scannell 3cb00c97e9 Add note about AArch64 support. 2020-05-06 14:15:18 -07:00
Adin Scannell f126de6a28 Add resource model. 2020-05-06 14:15:18 -07:00
Adin Scannell b6ba247fa6 Update main landing page. 2020-05-06 14:15:18 -07:00