If you do not finish during the lecture period, please finish it as homework.
Write a Cgo program that creates a new SQLITE database file and executes the following statements:
create table if not exists students (id integer not null primary key autoincrement, name text);
insert into students (name) values ('Your Name');
insert into students (name) values ('Another Name');
Do not use any GitHub libraries, but write your own Cgo wrapper. Verify the content of the database using any SQLITE inspector (e.g. IntelliJ or https://sqlitebrowser.org/).
Windows users can use the Windows Subsystem for Linux and install the following packages:
sudo apt install gcc golang sqlite3 libsqlite3-dev
# prepare chroot
mkdir -p jail/{bin,lib,lib64}
cp -v /bin/{bash,ls,touch,rm} jail/bin
for i in $(ldd /bin/bash | egrep -o '/lib.*.\.[0-9]'); do cp -v --parents "$i" jail; done
for i in $(ldd /bin/ls | egrep -o '/lib.*.\.[0-9]'); do cp -v --parents "$i" jail; done
for i in $(ldd /bin/touch | egrep -o '/lib.*.\.[0-9]'); do cp -v --parents "$i" jail; done
for i in $(ldd /bin/rm | egrep -o '/lib.*.\.[0-9]'); do cp -v --parents "$i" jail; done
# run chroot
sudo chroot jail
func main() {
switch os.Args[1] {
case "run":
func must(err error) {
if err != nil {
func run() {
log.Printf("Running %v \n", os.Args[1:])
cmd := exec.Command(os.Args[2], os.Args[3:]...)
cmd.Stdin = os.Stdin
cmd.Stdout = os.Stdout
cmd.Stderr = os.Stderr
- Try changing the hostname. What is the hostname if you exit the container?
- What is the pid?
cmd.SysProcAttr = &syscall.SysProcAttr{
Cloneflags: syscall.CLONE_NEWUTS | syscall.CLONE_NEWPID | syscall.CLONE_NEWNS,
Unshareflags: syscall.CLONE_NEWNS,
- Try changing the hostname again. What is the hostname if you exit the container?
- Call
. What do you see?
- Copy the run function and name the copy child().
- Remove cmd.SysProcAttr in the child() function.
- Modify the run() function to execute the following instead:
cmd := exec.Command("/proc/self/exe", append([]string{"child"}, os.Args[2:]...)...)
- Call
. What do you see?
Create a complete chroot environment. For Debian based linux systems, you might use e.g.
sudo debootstrap buster /jail http://deb.debian.org/debian
In the child() function, add the following code:
must(syscall.Chroot("/jail")) // local fs
must(syscall.Mount("proc", "proc", "proc", 0, ""))
must(syscall.Unmount("proc", 0))
- Call
. What do you see?
Use cgroups (/sys/fs/cgroup/
) to limit the container resource consumption.
Test your program!