mirror of
https://github.com/GoogleContainerTools/kaniko
synced 2026-09-30 14:23:14 +02:00
* fix: getUIDandGID is able to resolve non-existing users and groups A common pattern in dockerfiles is to provide a plain uid and gid number, which doesn't neccesarily exist inside the os. Signed-off-by: Höhl, Lukas <lukas.hoehl@accso.de> * test: add chown dockerfile Signed-off-by: Höhl, Lukas <lukas.hoehl@accso.de> * chore: format Signed-off-by: Höhl, Lukas <lukas.hoehl@accso.de> * chore: add comment Signed-off-by: Höhl, Lukas <lukas.hoehl@accso.de> * tests: fix chown dockerfile Signed-off-by: Höhl, Lukas <lukas.hoehl@accso.de> * refactor: split up getIdsFromUsernameAndGroup func Signed-off-by: Höhl, Lukas <lukas.hoehl@accso.de> * fix: implement raw uid logic for LookupUser Signed-off-by: Höhl, Lukas <lukas.hoehl@accso.de> * test: add dockerfiles for integration test * fix: lookup user error message * test: add dockerfiles for non-existing user testcase * fix: forgot error check * tests: fix syscall credentials test * chore: add debug output for copy command * tests: set specific gid for integration dockerfile * tests: fix syscall credentials test github runner had the exact uid that i was testing on, so the groups were not empty Signed-off-by: Höhl, Lukas <lukas.hoehl@accso.de> * tests: fix test script Signed-off-by: Höhl, Lukas <lukas.hoehl@accso.de> * chore: apply golangci lint checks Signed-off-by: Höhl, Lukas <lukas.hoehl@accso.de> * fix: reset file ownership in createFile if not root owned Signed-off-by: Höhl, Lukas <lukas.hoehl@accso.de> * chore: logrus.Debugf missed format variable Signed-off-by: Höhl, Lukas <lukas.hoehl@accso.de> * chore(test-script): remove go html coverage Signed-off-by: Höhl, Lukas <lukas.hoehl@accso.de> * test(k8s): increase wait timeout Signed-off-by: Höhl, Lukas <lukas.hoehl@accso.de>
63 lines
1.4 KiB
Go
63 lines
1.4 KiB
Go
/*
|
|
Copyright 2020 Google LLC
|
|
|
|
Licensed under the Apache License, Version 2.0 (the "License");
|
|
you may not use this file except in compliance with the License.
|
|
You may obtain a copy of the License at
|
|
|
|
http://www.apache.org/licenses/LICENSE-2.0
|
|
|
|
Unless required by applicable law or agreed to in writing, software
|
|
distributed under the License is distributed on an "AS IS" BASIS,
|
|
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
|
See the License for the specific language governing permissions and
|
|
limitations under the License.
|
|
*/
|
|
|
|
package util
|
|
|
|
import (
|
|
"fmt"
|
|
"strconv"
|
|
"syscall"
|
|
|
|
"github.com/pkg/errors"
|
|
"github.com/sirupsen/logrus"
|
|
)
|
|
|
|
func SyscallCredentials(userStr string) (*syscall.Credential, error) {
|
|
uid, gid, err := getUIDAndGIDFromString(userStr, true)
|
|
if err != nil {
|
|
return nil, errors.Wrap(err, "get uid/gid")
|
|
}
|
|
|
|
u, err := LookupUser(fmt.Sprint(uid))
|
|
if err != nil {
|
|
return nil, errors.Wrap(err, "lookup")
|
|
}
|
|
logrus.Infof("Util.Lookup returned: %+v", u)
|
|
|
|
// initiliaze empty
|
|
groups := []uint32{}
|
|
|
|
gidStr, err := groupIDs(u)
|
|
if err != nil {
|
|
return nil, errors.Wrap(err, "group ids for user")
|
|
}
|
|
|
|
for _, g := range gidStr {
|
|
i, err := strconv.ParseUint(g, 10, 32)
|
|
if err != nil {
|
|
return nil, errors.Wrap(err, "parseuint")
|
|
}
|
|
|
|
groups = append(groups, uint32(i))
|
|
}
|
|
|
|
return &syscall.Credential{
|
|
Uid: uid,
|
|
Gid: gid,
|
|
Groups: groups,
|
|
}, nil
|
|
}
|