tira-io / tira

The source code for the TIRA Shared Task Platform
https://www.tira.io
MIT License
14 stars 8 forks source link

Ubuntu 20 server image has problems with docker during sandboxing #43

Closed mam10eks closed 3 years ago

mam10eks commented 3 years ago

The ubuntu20 image uses docker installed in snap.

During sandboxing, /snap/bin is not part of the PATH, and as a result, docker does not work out-of-the box during sandboxing.

Following questions:

Why are the environment variables different during sandboxing?

Sandboxing:

SHELL=/bin/bash
PWD=/home/ir-lab-uh-t1-luke-skywalker/app LOGNAME=ir-lab-uh-t1-luke-skywalker
XDG_SESSION_TYPE=tty _=/usr/bin/env MOTD_SHOWN=pam
HOME=/home/ir-lab-uh-t1-luke-skywalker
LANG=C.UTF-8
SSH_CONNECTION=141.54.132.42 33278 10.0.5.100 22
XDG_SESSION_CLASS=user TERM=xterm
USER=ir-lab-uh-t1-luke-skywalker
SHLVL=1 XDG_SESSION_ID=5
XDG_RUNTIME_DIR=/run/user/1001
SSH_CLIENT=141.54.132.42 33278 22
LC_ALL=en_US.UTF-8
PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/usr/games:/usr/local/games DBUS_SESSION_BUS_ADDRESS=unix:path=/run/user/1001/bus
SSH_TTY=/dev/pts/0
OLDPWD=/home/ir-lab-uh-t1-luke-skywalker

During login via ssh:

SHELL=/bin/bash
PWD=/home/ir-lab-uh-t1-luke-skywalker
LOGNAME=ir-lab-uh-t1-luke-skywalker
XDG_SESSION_TYPE=tty
MOTD_SHOWN=pam
HOME=/home/ir-lab-uh-t1-luke-skywalker
LANG=C.UTF-8
LS_COLORS=rs=0:di=01;34:ln=01;36:mh=00:pi=40;33:so=01;35:do=01;35:bd=40;33;01:cd=40;33;01:or=40;31;01:mi=00:su=37;41:sg=30;43:ca=30;41:tw=30;42:ow=34;42:st=37;44:ex=01;32:*.tar=01;31:*.tgz=01;31:*.arc=01;31:*.arj=01;31:*.taz=01;31:*.lha=01;31:*.lz4=01;31:*.lzh=01;31:*.lzma=01;31:*.tlz=01;31:*.txz=01;31:*.tzo=01;31:*.t7z=01;31:*.zip=01;31:*.z=01;31:*.dz=01;31:*.gz=01;31:*.lrz=01;31:*.lz=01;31:*.lzo=01;31:*.xz=01;31:*.zst=01;31:*.tzst=01;31:*.bz2=01;31:*.bz=01;31:*.tbz=01;31:*.tbz2=01;31:*.tz=01;31:*.deb=01;31:*.rpm=01;31:*.jar=01;31:*.war=01;31:*.ear=01;31:*.sar=01;31:*.rar=01;31:*.alz=01;31:*.ace=01;31:*.zoo=01;31:*.cpio=01;31:*.7z=01;31:*.rz=01;31:*.cab=01;31:*.wim=01;31:*.swm=01;31:*.dwm=01;31:*.esd=01;31:*.jpg=01;35:*.jpeg=01;35:*.mjpg=01;35:*.mjpeg=01;35:*.gif=01;35:*.bmp=01;35:*.pbm=01;35:*.pgm=01;35:*.ppm=01;35:*.tga=01;35:*.xbm=01;35:*.xpm=01;35:*.tif=01;35:*.tiff=01;35:*.png=01;35:*.svg=01;35:*.svgz=01;35:*.mng=01;35:*.pcx=01;35:*.mov=01;35:*.mpg=01;35:*.mpeg=01;35:*.m2v=01;35:*.mkv=01;35:*.webm=01;35:*.ogm=01;35:*.mp4=01;35:*.m4v=01;35:*.mp4v=01;35:*.vob=01;35:*.qt=01;35:*.nuv=01;35:*.wmv=01;35:*.asf=01;35:*.rm=01;35:*.rmvb=01;35:*.flc=01;35:*.avi=01;35:*.fli=01;35:*.flv=01;35:*.gl=01;35:*.dl=01;35:*.xcf=01;35:*.xwd=01;35:*.yuv=01;35:*.cgm=01;35:*.emf=01;35:*.ogv=01;35:*.ogx=01;35:*.aac=00;36:*.au=00;36:*.flac=00;36:*.m4a=00;36:*.mid=00;36:*.midi=00;36:*.mka=00;36:*.mp3=00;36:*.mpc=00;36:*.ogg=00;36:*.ra=00;36:*.wav=00;36:*.oga=00;36:*.opus=00;36:*.spx=00;36:*.xspf=00;36:
SSH_CONNECTION=141.54.132.159 52202 10.0.5.100 22
LESSCLOSE=/usr/bin/lesspipe %s %s
XDG_SESSION_CLASS=user
TERM=xterm-256color
LESSOPEN=| /usr/bin/lesspipe %s
USER=ir-lab-uh-t1-luke-skywalker
SHLVL=1
XDG_SESSION_ID=7
XDG_RUNTIME_DIR=/run/user/1001
SSH_CLIENT=141.54.132.159 52202 22
XDG_DATA_DIRS=/usr/local/share:/usr/share:/var/lib/snapd/desktop
PATH=/home/ir-lab-uh-t1-luke-skywalker/.local/bin:/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/usr/games:/usr/local/games:/snap/bin
DBUS_SESSION_BUS_ADDRESS=unix:path=/run/user/1001/bus
SSH_TTY=/dev/pts/0
_=/usr/bin/env

Especially the the differences in PATH and LC_ALL are interesting.

Should we install a new ubuntu20 image?

Should we add some mandatory checks to ensure that a virtual machine image is valid? Which software must be installed? How should we test that it works within sandboxing and without sandboxing?

mam10eks commented 3 years ago

I found that tira vm-ssh sets some environment variables different compared to when I use plain ssh. That would also be the solution to the problem above.

mam10eks commented 3 years ago
cakiki commented 3 years ago

@mam10eks: I have added a new .ova file to the ceph with a "normal" docker installation: tira-ubuntu-20-04-server-docker-hotfix.ova

Do you have a test workflow you can use on this?

mam10eks commented 3 years ago

I have tested it (just run a docker bash, during sandboxing and without sandboxing) and it worked well. I.e. it this ticket can be closed now.