crosvm: plugin: use create_sandbox_minijail() for plugin

create_plugin_jail() and create_sandbox_minijail() do the same settings
except (1) `RLIMIT_NOFILE` and (2) plugin jail does not support embeded
bpf seccomp filter. But both difference won't be a problem.

(1) Given that Parallels plugin is closed source we will not be able t
ocame up with a reasonable limit, so it might need to go the way GPU
device does it and set the limit to 32K.

(2) We validate seccomp_policy_dir in jail_config is not none.

The fallback logic for the pivot root path for plugin is a bit changed,
but it should not be a problem.

* before: cfg.plugin_root > DEFAULT_PIVOT_ROOT env > "/var/empty"
* after: cfg.plugin_root > jail_config.pivot_root > DEFAULT_PIVOT_ROOT
  env > "/var/empty"

This migration also introduce minor updates to jail helpers.

* create_base_minijail() validates root path to be absolute path.
  * otherwise, chroot fails and minijail fails.
* The source for mounting proc is changed ("/proc" -> "proc").
  * "proc" looks the proper source to mount according to proc(5) man
    page.
  * "/proc" as the source was introduced by https://crrev.com/c/1717739,
    but it looks they didn't have any concrete reason for it.

BUG=b:268281422
TEST=./tools/run_tests2
TEST=tast run $DUT arc.PlayStore.vm

Change-Id: Ie014cadf3cec4a049ef783546782209e26d9902a
Reviewed-on: https://chromium-review.googlesource.com/c/crosvm/crosvm/+/4262049
Reviewed-by: Dmitry Torokhov <dtor@chromium.org>
Commit-Queue: Shin Kawamura <kawasin@google.com>
2 files changed
tree: 7f8f6c69dacc04b2b5022605f5feea14e79ea46f
  1. .cargo/
  2. .config/
  3. .devcontainer/
  4. .github/
  5. .vscode/
  6. aarch64/
  7. acpi_tables/
  8. anti_tamper/
  9. arch/
  10. argh_helpers/
  11. base/
  12. bit_field/
  13. broker_ipc/
  14. common/
  15. crash_report/
  16. cros_async/
  17. cros_fdt/
  18. cros_tracing/
  19. crosvm-fuzz/
  20. crosvm_cli/
  21. crosvm_control/
  22. crosvm_plugin/
  23. devices/
  24. disk/
  25. docs/
  26. e2e_tests/
  27. fuse/
  28. gpu_display/
  29. hypervisor/
  30. infra/
  31. io_uring/
  32. jail/
  33. kernel_cmdline/
  34. kernel_loader/
  35. kvm/
  36. kvm_sys/
  37. libcras_stub/
  38. linux_input_sys/
  39. logo/
  40. media/
  41. metrics/
  42. net_sys/
  43. net_util/
  44. power_monitor/
  45. prebuilts/
  46. proto_build_tools/
  47. protos/
  48. qcow_utils/
  49. resources/
  50. rutabaga_gfx/
  51. sandbox/
  52. serde_keyvalue/
  53. src/
  54. swap/
  55. system_api/
  56. tests/
  57. third_party/
  58. tools/
  59. tpm2/
  60. tpm2-sys/
  61. tube_transporter/
  62. usb_sys/
  63. usb_util/
  64. vfio_sys/
  65. vhost/
  66. virtio_sys/
  67. vm_control/
  68. vm_memory/
  69. win_audio/
  70. win_util/
  71. x86_64/
  72. .dockerignore
  73. .gitignore
  74. .gitmodules
  75. .rustfmt.toml
  76. ARCHITECTURE.md
  77. Cargo.lock
  78. Cargo.toml
  79. CONTRIBUTING.md
  80. DIR_METADATA
  81. LICENSE
  82. mypy.ini
  83. OWNERS
  84. OWNERS_COUNCIL
  85. PRESUBMIT.cfg
  86. pyproject.toml
  87. README.chromeos.md
  88. README.md
  89. rust-toolchain
README.md

crosvm - The ChromeOS Virtual Machine Monitor

crosvm is a virtual machine monitor (VMM) based on Linux’s KVM hypervisor, with a focus on simplicity, security, and speed. crosvm is intended to run Linux guests, originally as a security boundary for running native applications on the ChromeOS platform. Compared to QEMU, crosvm doesn’t emulate architectures or real hardware, instead concentrating on paravirtualized devices, such as the virtio standard.

crosvm is currently used to run Linux/Android guests on ChromeOS devices.

Logo