- hard links in the rootfs were written as zero-size entries with no inode set (all zero), so the kernel could link them to the wrong file; assign a synthetic inode per (device, inode) group. - build the cpio archive by streaming entries to disk instead of holding the whole archive in memory. - the VM command was joined into a single string and shell-expanded in the guest, mangling quotes and nested commands; pass the argv base64-encoded (ECR_ARGV) and exec it verbatim. - parse ecr parameters from /proc/cmdline in the init script, set the hostname via procfs (arch has no hostname binary), and give the serial console a moment to drain before poweroff.
52 lines
1005 B
TOML
52 lines
1005 B
TOML
[package]
|
|
name = "ecr"
|
|
version = "0.1.0"
|
|
edition = "2021"
|
|
rust-version = "1.77"
|
|
description = "Enter chroot environments with Linux namespaces"
|
|
license = "MIT"
|
|
authors = ["Valentin Haudiquet"]
|
|
|
|
[dependencies]
|
|
# CLI parsing
|
|
clap = { version = "4", features = ["derive", "env"] }
|
|
|
|
# Config parsing
|
|
serde = { version = "1", features = ["derive"] }
|
|
serde_yaml = "0.9"
|
|
|
|
# HTTP downloads
|
|
reqwest = { version = "0.13", features = ["blocking", "stream"] }
|
|
|
|
# Tarball extraction
|
|
tar = "0.4"
|
|
flate2 = "1"
|
|
xz2 = "0.1"
|
|
zstd = "0.13"
|
|
|
|
# Unix syscall bindings
|
|
nix = { version = "0.31", features = ["fs", "mount", "sched", "signal", "user", "process", "hostname"] }
|
|
|
|
# Temp directories
|
|
tempfile = "3"
|
|
|
|
# Error handling
|
|
anyhow = "1"
|
|
|
|
# Utilities
|
|
dirs = "6"
|
|
which = "7"
|
|
cpio = "0.4"
|
|
base64 = "0.22"
|
|
tokio = { version = "1", features = ["rt-multi-thread", "macros", "io-util"] }
|
|
futures-util = "0.3"
|
|
indicatif = "0.18"
|
|
serde_json = "1"
|
|
libc = "0.2"
|
|
users = "0.11"
|
|
|
|
[profile.release]
|
|
strip = true
|
|
opt-level = "z"
|
|
lto = true
|