aboutsummaryrefslogtreecommitdiffhomepage
path: root/container
diff options
context:
space:
mode:
authorOphestra <cat@gensokyo.uk>2025-08-01 18:58:42 +0900
committerOphestra <cat@gensokyo.uk>2025-08-01 18:59:06 +0900
commit547a2adaa488556f0504e186c5c1dfb0e679c935 (patch)
tree8c2f0fd5190d3e460672f5f7be50024baac15372 /container
parentc02948e1557551a94b5366bf186148b8275598c1 (diff)
container/mount: pass tmpfs flags
Signed-off-by: Ophestra <cat@gensokyo.uk>
Diffstat (limited to 'container')
-rw-r--r--container/container_test.go15
-rw-r--r--container/mount.go4
-rw-r--r--container/ops.go20
3 files changed, 28 insertions, 11 deletions
diff --git a/container/container_test.go b/container/container_test.go
index 190fa5b5..bc4999e5 100644
--- a/container/container_test.go
+++ b/container/container_test.go
@@ -28,7 +28,9 @@ const (
ignore = "\x00"
ignoreV = -1
- pathWantMnt = "/etc/hakurei/want-mnt"
+ pathPrefix = "/etc/hakurei/"
+ pathWantMnt = pathPrefix + "want-mnt"
+ pathReadonly = pathPrefix + "readonly"
)
var containerTestCases = []struct {
@@ -62,7 +64,7 @@ var containerTestCases = []struct {
new(container.Ops).
Tmpfs(hst.Tmp, 0, 0755),
[]*vfs.MountInfoEntry{
- ent("/", hst.Tmp, "rw,nosuid,nodev,relatime", "tmpfs", "tmpfs", ignore),
+ ent("/", hst.Tmp, "rw,nosuid,nodev,relatime", "tmpfs", "ephemeral", ignore),
},
9, 9, nil, 0, seccomp.PresetStrict},
{"dev", true, true /* go test output is not a tty */, false,
@@ -140,6 +142,7 @@ func TestContainer(t *testing.T) {
c.HostNet = tc.net
c.
+ Readonly(pathReadonly, 0755).
Tmpfs("/tmp", 0, 0755).
Place("/etc/hostname", []byte(c.Hostname))
// needs /proc to check mountinfo
@@ -158,8 +161,10 @@ func TestContainer(t *testing.T) {
}
mnt = append(mnt, tc.mnt...)
mnt = append(mnt,
+ // Readonly(pathReadonly, 0755)
+ ent("/", pathReadonly, "ro,nosuid,nodev", "tmpfs", "readonly", ignore),
// Tmpfs("/tmp", 0, 0755)
- ent("/", "/tmp", "rw,nosuid,nodev,relatime", "tmpfs", "tmpfs", ignore),
+ ent("/", "/tmp", "rw,nosuid,nodev,relatime", "tmpfs", "ephemeral", ignore),
// Place("/etc/hostname", []byte(hostname))
ent(ignore, "/etc/hostname", "ro,nosuid,nodev,relatime", "tmpfs", "rootfs", ignore),
// Proc("/proc")
@@ -309,6 +314,10 @@ func init() {
return fmt.Errorf("/etc/hostname: %q, want %q", string(p), wantHost)
}
+ if _, err := os.Create(pathReadonly + "/nonexistent"); !errors.Is(err, syscall.EROFS) {
+ return err
+ }
+
{
var fail bool
diff --git a/container/mount.go b/container/mount.go
index 52563d78..12093d47 100644
--- a/container/mount.go
+++ b/container/mount.go
@@ -97,7 +97,7 @@ func remountWithFlags(n *vfs.MountInfoNode, mf uintptr) error {
return nil
}
-func mountTmpfs(fsname, name string, size int, perm os.FileMode) error {
+func mountTmpfs(fsname, name string, flags uintptr, size int, perm os.FileMode) error {
target := toSysroot(name)
if err := os.MkdirAll(target, parentPerm(perm)); err != nil {
return wrapErrSelf(err)
@@ -107,7 +107,7 @@ func mountTmpfs(fsname, name string, size int, perm os.FileMode) error {
opt += fmt.Sprintf(",size=%d", size)
}
return wrapErrSuffix(
- Mount(fsname, target, "tmpfs", MS_NOSUID|MS_NODEV, opt),
+ Mount(fsname, target, "tmpfs", flags, opt),
fmt.Sprintf("cannot mount tmpfs on %q:", name))
}
diff --git a/container/ops.go b/container/ops.go
index 85291da3..1fd4963c 100644
--- a/container/ops.go
+++ b/container/ops.go
@@ -170,7 +170,7 @@ func (d MountDevOp) apply(params *Params) error {
}
target := toSysroot(v)
- if err := mountTmpfs("devtmpfs", v, 0, params.ParentPerm); err != nil {
+ if err := mountTmpfs("devtmpfs", v, MS_NOSUID|MS_NODEV, 0, params.ParentPerm); err != nil {
return err
}
@@ -280,14 +280,22 @@ func init() { gob.Register(new(MountTmpfsOp)) }
// Tmpfs appends an [Op] that mounts tmpfs on container path [MountTmpfsOp.Path].
func (f *Ops) Tmpfs(dest string, size int, perm os.FileMode) *Ops {
- *f = append(*f, &MountTmpfsOp{dest, size, perm})
+ *f = append(*f, &MountTmpfsOp{"ephemeral", dest, MS_NOSUID | MS_NODEV, size, perm})
+ return f
+}
+
+// Readonly appends an [Op] that mounts read-only tmpfs on container path [MountTmpfsOp.Path].
+func (f *Ops) Readonly(dest string, perm os.FileMode) *Ops {
+ *f = append(*f, &MountTmpfsOp{"readonly", dest, MS_RDONLY | MS_NOSUID | MS_NODEV, 0, perm})
return f
}
type MountTmpfsOp struct {
- Path string
- Size int
- Perm os.FileMode
+ FSName string
+ Path string
+ Flags uintptr
+ Size int
+ Perm os.FileMode
}
func (t *MountTmpfsOp) early(*Params) error { return nil }
@@ -298,7 +306,7 @@ func (t *MountTmpfsOp) apply(*Params) error {
if t.Size < 0 || t.Size > math.MaxUint>>1 {
return msg.WrapErr(EBADE, fmt.Sprintf("size %d out of bounds", t.Size))
}
- return mountTmpfs("tmpfs", t.Path, t.Size, t.Perm)
+ return mountTmpfs(t.FSName, t.Path, t.Flags, t.Size, t.Perm)
}
func (t *MountTmpfsOp) Is(op Op) bool { vt, ok := op.(*MountTmpfsOp); return ok && *t == *vt }