Add support for the Dockerfile USER directive so that the container's CMD/ENTRYPOINT runs as the configured user instead of root. Changes: - inject.rs: Add user field to Config struct, write /slim/user at build time - build.rs: Pass config.user through to inject() - slim-init.sh: Read /slim/user and drop privileges via su before executing the command. Numeric uids are resolved to usernames via /etc/passwd (BusyBox su does not accept numeric args). When dropping privileges, run as a child (not exec) so PID 1 stays root and can poweroff after the command exits. - test.sh: Add test_user verifying build-time CMD and --cmd override both run as the configured user Closes #7
This commit is contained in:
@@ -103,6 +103,39 @@ EOF
|
||||
rm -rf "$work"
|
||||
}
|
||||
|
||||
test_user() {
|
||||
echo "=== Testing USER directive ==="
|
||||
|
||||
work="$(mktemp -d)"
|
||||
img="slim-test-user"
|
||||
|
||||
cat > "$work/Containerfile" <<'EOF'
|
||||
FROM alpine:latest
|
||||
RUN adduser -D -u 1500 testuser
|
||||
USER testuser
|
||||
CMD ["/bin/sh", "-c", "echo USER_BUILD_OK:$(id -u):$(whoami); poweroff -f"]
|
||||
EOF
|
||||
|
||||
echo "-- Building container image with USER directive..."
|
||||
if ! podman build --network=none -t "$img" -f "$work/Containerfile" >/dev/null 2>&1; then
|
||||
report fail "USER directive (podman build failed)"
|
||||
rm -rf "$work"
|
||||
return
|
||||
fi
|
||||
|
||||
echo "-- Test 1: build-time CMD runs as USER"
|
||||
"$SLIM_BIN" build qcow2 "$img" >/dev/null 2>&1
|
||||
output=$(timeout "$TIMEOUT" "$SLIM_BIN" run "$img" 2>&1 || true)
|
||||
check_output "$output" "USER_BUILD_OK:1500:testuser" "USER build-time CMD runs as testuser"
|
||||
|
||||
echo "-- Test 2: run --cmd override runs as USER"
|
||||
output=$(timeout "$TIMEOUT" "$SLIM_BIN" run "$img" --cmd 'echo USER_RUN_OK:$(id -u):$(whoami); poweroff -f' 2>&1 || true)
|
||||
check_output "$output" "USER_RUN_OK:1500:testuser" "USER run --cmd override runs as testuser"
|
||||
|
||||
cleanup "$img" "$img"
|
||||
rm -rf "$work"
|
||||
}
|
||||
|
||||
test_service() {
|
||||
echo "=== Testing nextcloud service ==="
|
||||
|
||||
@@ -171,6 +204,8 @@ cargo build 2>&1
|
||||
test_distro "alpine" "alpine:latest" ""
|
||||
test_distro "archlinux" "archlinux:latest" "RUN pacman -Sy --noconfirm iproute2 wget; pacman -Sc --noconfirm"
|
||||
|
||||
test_user
|
||||
|
||||
test_service
|
||||
|
||||
echo ""
|
||||
|
||||
Reference in New Issue
Block a user