hooks

package
v4.6.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 5, 2026 License: BSD-3-Clause Imports: 16 Imported by: 0

Documentation

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

This section is empty.

Types

type NativeHook

type NativeHook struct {
	// Name for the hook, will be set to the hook filename if not specified.
	Name string `json:"name"`
	// Version of the hook structure - 1.0.0 is expected
	Version string `json:"version"`
	// Hook as an OCI runtime-spec Hook struct
	Hook specs.Hook `json:"hook"`
	// When the hook should run
	When cchooks.When `json:"when"`
	// Stages in the container lifecycle at which the hook should run
	Stages []string `json:"stages"`
	// Privileged indicates the hook should be executed only in setuid, and with escalated privilege.
	Privileged bool `json:"privileged"`
}

NativeHook represents a hook that can be executed by the native runtime. It has the same basic structure as the containers/common current.Hook type, with the addition of a boolean 'Privileged' field that marks the hook for privileged escalation in the setuid flow, and a string 'Name' field.

func LoadNativeHooks

func LoadNativeHooks(privileged bool) ([]NativeHook, error)

LoadNativeHooks loads all hooks from JSON files in the configuration directory. If privileged is false, hooks that specify `Privileged: true` are skipped, and there are no ownership checks. If privileged is true, all hooks are loaded and must have `root:root` ownership.

func (*NativeHook) Run

func (n *NativeHook) Run(state specs.State, allowPrivileged bool) error

Run executes the NativeHook binary with configured args and env. If allowPrivileged is false, a hook with `Privileged=true` will refuse to run. If allowPrivileged is true, a hook with `Privileged=true` will be run as root. A JSON OCI runtime-spec state structure is passed over STDIN. A non-standard `SINGULARITY_CONTAINER_PID` env var is added for the convenience of hooks that would otherwise need to parse the PID from the state JSON. A `SINGULARITY_HOOK_PRIVILEGED` env var is set if the hook is being run with privilege.

func (*NativeHook) Validate

func (n *NativeHook) Validate() error

Validate checks that a NativeHook is supported by the runtime. At present, only poststart hooks that run always are supported.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL