From dbcbe0ab4de2dbadccdf8cd2817185df0e6469c6 Mon Sep 17 00:00:00 2001 From: "Lance R. Vick" Date: Tue, 27 Jun 2023 16:33:03 -0700 Subject: [PATCH 1/2] Create required nitro dirs at the daemon and container level --- src/images/enclave/Dockerfile | 2 ++ src/qos_enclave/src/main.rs | 6 +++++- 2 files changed, 7 insertions(+), 1 deletion(-) diff --git a/src/images/enclave/Dockerfile b/src/images/enclave/Dockerfile index 767d93d2..c0dd506a 100644 --- a/src/images/enclave/Dockerfile +++ b/src/images/enclave/Dockerfile @@ -2,6 +2,8 @@ FROM scratch LABEL org.opencontainers.image.source=https://github.com/tkhq/qos ARG BIN ARG EIF +VOLUME /run/nitro_enclaves +VOLUME /var/log/run/nitro_enclaves COPY ${BIN} /qos_enclave COPY ${EIF} /nitro.eif ENTRYPOINT ["/qos_enclave"] diff --git a/src/qos_enclave/src/main.rs b/src/qos_enclave/src/main.rs index a7c35fb7..2ccac9d4 100644 --- a/src/qos_enclave/src/main.rs +++ b/src/qos_enclave/src/main.rs @@ -86,11 +86,15 @@ fn boot() -> String { }; println!("{:?}", run_args); - // Socket directory must exist or Nitro SDK crashes with generic error + // Socket/log directories must exist or Nitro SDK crashes generically if !Path::new("/run/nitro_enclaves").is_dir() { create_dir_all("/run/nitro_enclaves") .expect("Failed to create /run/nitro_enclaves"); } + if !Path::new("/var/log/nitro_enclaves").is_dir() { + create_dir_all("/var/log/nitro_enclaves") + .expect("Failed to create /var/log/nitro_enclaves"); + } let logger = init_logger() .map_err(|e| e.set_action("Logger initialization".to_string())) From eeebaed4a6f20a37668de8c830aeed96722bd534 Mon Sep 17 00:00:00 2001 From: "Lance R. Vick" Date: Tue, 27 Jun 2023 17:27:21 -0700 Subject: [PATCH 2/2] fix enclave logdir name --- src/images/enclave/Dockerfile | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/src/images/enclave/Dockerfile b/src/images/enclave/Dockerfile index c0dd506a..f32a3297 100644 --- a/src/images/enclave/Dockerfile +++ b/src/images/enclave/Dockerfile @@ -3,7 +3,7 @@ LABEL org.opencontainers.image.source=https://github.com/tkhq/qos ARG BIN ARG EIF VOLUME /run/nitro_enclaves -VOLUME /var/log/run/nitro_enclaves +VOLUME /var/log/nitro_enclaves COPY ${BIN} /qos_enclave COPY ${EIF} /nitro.eif ENTRYPOINT ["/qos_enclave"]