crosvm: plugin: use create_sandbox_minijail() for plugin
create_plugin_jail() and create_sandbox_minijail() do the same settings
except (1) `RLIMIT_NOFILE` and (2) plugin jail does not support embeded
bpf seccomp filter. But both difference won't be a problem.
(1) Given that Parallels plugin is closed source we will not be able t
ocame up with a reasonable limit, so it might need to go the way GPU
device does it and set the limit to 32K.
(2) We validate seccomp_policy_dir in jail_config is not none.
The fallback logic for the pivot root path for plugin is a bit changed,
but it should not be a problem.
* before: cfg.plugin_root > DEFAULT_PIVOT_ROOT env > "/var/empty"
* after: cfg.plugin_root > jail_config.pivot_root > DEFAULT_PIVOT_ROOT
env > "/var/empty"
This migration also introduce minor updates to jail helpers.
* create_base_minijail() validates root path to be absolute path.
* otherwise, chroot fails and minijail fails.
* The source for mounting proc is changed ("/proc" -> "proc").
* "proc" looks the proper source to mount according to proc(5) man
page.
* "/proc" as the source was introduced by https://crrev.com/c/1717739,
but it looks they didn't have any concrete reason for it.
BUG=b:268281422
TEST=./tools/run_tests2
TEST=tast run $DUT arc.PlayStore.vm
Change-Id: Ie014cadf3cec4a049ef783546782209e26d9902a
Reviewed-on: https://chromium-review.googlesource.com/c/crosvm/crosvm/+/4262049
Reviewed-by: Dmitry Torokhov <dtor@chromium.org>
Commit-Queue: Shin Kawamura <kawasin@google.com>
crosvm is a virtual machine monitor (VMM) based on Linux’s KVM hypervisor, with a focus on simplicity, security, and speed. crosvm is intended to run Linux guests, originally as a security boundary for running native applications on the ChromeOS platform. Compared to QEMU, crosvm doesn’t emulate architectures or real hardware, instead concentrating on paravirtualized devices, such as the virtio standard.
crosvm is currently used to run Linux/Android guests on ChromeOS devices.