| #!/bin/bash |
| # Copyright (c) 2026, The OpenThread Authors. |
| # All rights reserved. |
| # |
| # Redistribution and use in source and binary forms, with or without |
| # modification, are permitted provided that the following conditions are met: |
| # 1. Redistributions of source code must retain the above copyright |
| # notice, this list of conditions and the following disclaimer. |
| # 2. Redistributions in binary form must reproduce the above copyright |
| # notice, this list of conditions and the following disclaimer in the |
| # documentation and/or other materials provided with the distribution. |
| # 3. Neither the name of the copyright holder nor the |
| # names of its contributors may be used to endorse or promote products |
| # derived from this software without specific prior written permission. |
| # |
| # THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" |
| # AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE |
| # IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE |
| # ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT HOLDER OR CONTRIBUTORS BE |
| # LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR |
| # CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF |
| # SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS |
| # INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN |
| # CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) |
| # ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE |
| # POSSIBILITY OF SUCH DAMAGE. |
| # |
| if [[ ${BASH_SOURCE[0]} == "${0}" ]]; then |
| echo "Error: This script must be sourced, not executed directly." >&2 |
| exit 1 |
| fi |
| |
| if [[ -n ${OT_ISOLATED_REEXEC:-} ]]; then |
| ip link set lo up |
| |
| if [[ -d /run ]]; then |
| mount -t tmpfs tmpfs /run |
| fi |
| |
| if [[ -d /var/run && ! -L /var/run ]]; then |
| mount -t tmpfs tmpfs /var/run |
| fi |
| |
| sudo() |
| { |
| while [[ $# -gt 0 ]]; do |
| case "$1" in |
| -E) |
| shift |
| ;; |
| --) |
| shift |
| break |
| ;; |
| -*) |
| echo "Error: unsupported mock sudo option: $1" >&2 |
| return 1 |
| ;; |
| *) |
| break |
| ;; |
| esac |
| done |
| |
| "$@" |
| } |
| |
| export -f sudo |
| return 0 |
| elif [[ $EUID -eq 0 ]]; then |
| # Isolation is not necessary |
| return 0 |
| elif ! unshare -nmr --kill-child true >/dev/null 2>&1; then |
| # Isolation is not supported or restricted (e.g., non-Linux or unprivileged userns disabled) |
| return 0 |
| fi |
| |
| # Unprivileged Linux: Re-exec inside unshare |
| export OT_ISOLATED_REEXEC=1 |
| |
| CALLER_SCRIPT="${BASH_SOURCE[${#BASH_SOURCE[@]} - 1]:-$0}" |
| exec unshare -nmr --kill-child bash "$CALLER_SCRIPT" "$@" |