#!/bin/bash
#(c) Copyright Barry Kauler, 31 January 2017. License: GPL V3 (/usr/share/doc/legal)
#Easy Linux script for Easy Containers, to run an isolated application.
#passed in parameter is name of executable, may have arguments $2 etc.
#if passed-in param is "sh[0-9]" then just run shell in a terminal
#170804 moved umount container/dev/* to stop-container

[ ! $1 ] && exit 1
EXE="$1"; shift
ARGS=''
[ $1 ] && while [ "$1" ]; do ARGS="$ARGS \"$1\""; shift; done #put quotes around each argument.

. /etc/rc.d/PUPSTATE #has BOOT_DEV, BOOT_FS, BOOT_DIR, WKG_DEV, WKG_FS, WKG_DIR, QSFS_PATH

#setup-container must have already been run.
CONTAINER="/mnt/${WKG_DEV}/${WKG_DIR}containers/${EXE}/container"
[ ! -d /mnt/${WKG_DEV}/${WKG_DIR}containers/${EXE}/container ] && exit 1 #precaution
#170225 start container, if not already...
if [ "$(mount | grep "containers/${EXE}")" == "" ];then
 start-container ${EXE}
 [ $? -ne 0 ] && exit 1
fi

. /mnt/${WKG_DEV}/${WKG_DIR}containers/${EXE}/configuration #has EC_XORG_SOCKET

#170317 seamonkey wants this...
if [ ! -s /mnt/${WKG_DEV}/${WKG_DIR}containers/${EXE}/.session/etc/machine-id ];then
 mkdir -p /mnt/${WKG_DEV}/${WKG_DIR}containers/${EXE}/.session/etc
 cp -a -f /etc/machine-id /mnt/${WKG_DEV}/${WKG_DIR}containers/${EXE}/.session/etc/
fi

case "$EC_XORG_SOCKET" in
 pipe)
  #this enables DISPLAY=localhost:0 inside the chroot:
  # -ly logs to syslog.
  if ! pidof socat; then
   socat -ly -d -d TCP-LISTEN:6000,fork,bind=localhost UNIX-CONNECT:/tmp/.X11-unix/X0 &
  fi
  ecDISPLAY='localhost:0'
 ;;
 *) #abstract
  ecDISPLAY=':0'
 ;;
esac

#namespaces
uOPTS=""
[ "$EC_NS_UNSHARE_MOUNT" == "true" ] && uOPTS="${uOPTS} -m --mount-proc"
[ "$EC_NS_UNSHARE_UTS" == "true" ] && uOPTS="${uOPTS} -u"
[ "$EC_NS_UNSHARE_IPC" == "true" ] && uOPTS="${uOPTS} -i"
[ "$EC_NS_UNSHARE_NETWORK" == "true" ] && uOPTS="${uOPTS} -n"
[ "$EC_NS_UNSHARE_PID" == "true" ] && uOPTS="${uOPTS} -p"
[ "$EC_NS_UNSHARE_USER" == "true" ] && uOPTS="${uOPTS} -U --setgroups=deny --map-root-user"

ENVI=""
[ "$EC_UNSHARE_ENV_VARS" == "true" ] && ENVI="env -i TERM=xterm DISPLAY=${ecDISPLAY}"

if [ "$EC_NS_UNSHARE_MOUNT" == "false" ];then
 busybox mount -o bind /proc ${CONTAINER}/proc
 busybox mount -o bind /sys ${CONTAINER}/sys
 busybox mount -o bind /dev ${CONTAINER}/dev
 busybox mount -o bind /tmp ${CONTAINER}/tmp
 busybox mount -o bind /dev/pts ${CONTAINER}/dev/pts
 busybox mount -o bind /dev/shm ${CONTAINER}/dev/shm
fi

#needed for internet access...
cp -f /etc/resolv.conf ${CONTAINER}/etc/resolv.conf

#--map-root-user needed if have -U, otherwise env will fail.
if [[ "$EXE" == sh[0-9] ]];then
 #urxvt -e unshare -piumU --fork --mount-proc --map-root-user --setgroups=deny env -i TERM=xterm DISPLAY=${ecDISPLAY} /bin/busybox chroot ${CONTAINER} /bin/sh
 #urxvt -e unshare ${uOPTS} --fork env -i TERM=xterm DISPLAY=${ecDISPLAY} /bin/busybox chroot ${CONTAINER} /bin/sh
 urxvt -e unshare ${uOPTS} --fork ${ENVI} /bin/busybox chroot ${CONTAINER} /ec-run /bin/sh
else
 #unshare -piumU --fork --mount-proc --map-root-user --setgroups=deny env -i TERM=xterm DISPLAY=${ecDISPLAY} /bin/busybox chroot ${CONTAINER} /ec-run ${EXE} ${ARGS}
 #unshare ${uOPTS} --fork env -i TERM=xterm DISPLAY=${ecDISPLAY} /bin/busybox chroot ${CONTAINER} /ec-run ${EXE} ${ARGS}
 unshare ${uOPTS} --fork ${ENVI} /bin/busybox chroot ${CONTAINER} /ec-run ${EXE} ${ARGS}
fi

#if [ "$EC_NS_UNSHARE_MOUNT" == "false" ];then
# busybox umount ${CONTAINER}/dev/shm
# busybox umount ${CONTAINER}/dev/pts
# busybox umount ${CONTAINER}/tmp
# busybox umount ${CONTAINER}/dev
# busybox umount ${CONTAINER}/sys
# busybox umount ${CONTAINER}/proc
#fi

##170225 the above umount's are necessary before run stop-container. 170804 no.
stop-container ${EXE}

##170317 quit seamonkey, reported dev busy, then stop-container failed umount 'container'...
#if [ "$EC_NS_UNSHARE_MOUNT" == "false" ];then
# if [ "$(busybox mount | grep "${CONTAINER}/dev")" != "" ];then
#  echo "trying again to umount 'dev' and 'container'..."
#  busybox umount ${CONTAINER}/dev
#  busybox umount ${CONTAINER}
# fi
#fi

#umount ./q_top1/dev/pts
#busybox umount ./q_top1/dev/pts

#umount ./q_top1/dev
#run this when logged in:
#mount -t proc proc /proc

#now using static /dev, run this when logged in:
#NO mount -t tmpfs -o size=${QTRFREERAM}k shmfs /dev/shm
#busybox mount -t tmpfs shmfs /dev/shm
#busybox mount -t devpts devpts /dev/pts
# but as /etc/fstab exists, just do this: busybox mount /dev/pts
# ...cannot "permission denied"

#'mp' works

#'leafpad' crashes
# The program 'leafpad' received an X Window System error.
# This probably reflects a bug in the program.
# The error was 'BadShmSeg (invalid shared segment parameter)'.
#...ah, runs the second time. ditto for geany. just get this crash 1st time try run an x app.

#'geany' works, console msg when open a file:
# (geany:3): GLib-GIO-WARNING **: Error creating IO channel for /proc/mounts: No such file or directory (g-file-error-quark, 4)
#...no /proc/mounts
#... forgot to run: mount -t proc proc /proc



