From 5d9e669d97ee53e3b6d4478d315319b59d5b402b Mon Sep 17 00:00:00 2001 From: Ophestra Date: Fri, 14 Mar 2025 00:21:20 +0900 Subject: sandbox: separate tmpfs function from op This is useful in the implementation of various other ops. Signed-off-by: Ophestra --- internal/sandbox/mount.go | 14 ++++++++++++++ 1 file changed, 14 insertions(+) (limited to 'internal/sandbox/mount.go') diff --git a/internal/sandbox/mount.go b/internal/sandbox/mount.go index 3c6ae2d8..3d3d63af 100644 --- a/internal/sandbox/mount.go +++ b/internal/sandbox/mount.go @@ -79,3 +79,17 @@ func bindMount(src, dest string, flags int) error { return fmsg.WrapErrorSuffix(syscall.Mount(source, target, "", mf, ""), fmt.Sprintf("cannot bind %q on %q:", src, dest)) } + +func mountTmpfs(name string, size int, perm os.FileMode) error { + target := toSysroot(name) + if err := os.MkdirAll(target, perm); err != nil { + return err + } + opt := fmt.Sprintf("mode=%#o", perm) + if size > 0 { + opt += fmt.Sprintf(",size=%d", size) + } + return fmsg.WrapErrorSuffix(syscall.Mount("tmpfs", target, "tmpfs", + syscall.MS_NOSUID|syscall.MS_NODEV, opt), + fmt.Sprintf("cannot mount tmpfs on %q:", name)) +} -- cgit v1.3.1