From: "'Felix Moessbauer' via isar-users" <isar-users@googlegroups.com>
To: isar-users@googlegroups.com
Cc: Felix Moessbauer <felix.moessbauer@siemens.com>,
Jan Kiszka <jan.kiszka@siemens.com>
Subject: [PATCH 1/1] isar-mounts: mount /run as tmpfs for systemd execution in chroot
Date: Wed, 23 Sep 2026 16:33:50 +0200 [thread overview]
Message-ID: <20260923143350.2086040-1-felix.moessbauer@siemens.com> (raw)
When running systemd inside the chroot, it might access /run and place
files there. These can have ownerships (like 0000) which require DAC
capabilities for traversing and removing. As this is tricky to achieve
across all cleanup code, we stick to the systemd file system hierarchy
and mount /run as a tmpfs. By that, all files below it will
automatically be dropped when leaving the namespace.
This solves cleanup issues on rootless like:
find: '<...>/rootfs/run/systemd/dissect-root': Permission denied
As we anyways cleanup the /run in do_rootfs_finalize (image only), this
does not change the content of the image. However, it improves the
reproduciblity of our internal rootfs' which can improve caching.
Reported-by: Jan Kiszka <jan.kiszka@siemens.com>
Signed-off-by: Felix Moessbauer <felix.moessbauer@siemens.com>
---
meta/classes-global/base.bbclass | 4 ++++
1 file changed, 4 insertions(+)
diff --git a/meta/classes-global/base.bbclass b/meta/classes-global/base.bbclass
index 8f81ab70..3d5d1c12 100644
--- a/meta/classes-global/base.bbclass
+++ b/meta/classes-global/base.bbclass
@@ -399,6 +399,10 @@ def insert_isar_mounts(d, rootfs, mounts):
lines.append('mount -t devpts -o noexec,nosuid,uid=5,mode=620,ptmxmode=666 none {}/dev/pts'.format(rootfs))
lines.append('( cd {}/dev; ln -sf pts/ptmx . )'.format(rootfs))
lines.append('mount -t tmpfs none {}/dev/shm'.format(rootfs))
+ # required by systemd file-system hierarchy
+ lines.append('mount -t tmpfs -o mode=0755 tmpfs {}/run'.format(rootfs))
+ # required by Debian policy 9.1.4
+ lines.append('mkdir {}/run/lock'.format(rootfs))
lines.append('mount -o bind /dev/random {}/dev/random'.format(rootfs))
lines.append('mount -o bind /dev/urandom {}/dev/urandom'.format(rootfs))
lines.append('mount -t proc none {}/proc'.format(rootfs))
--
2.55.0
--
You received this message because you are subscribed to the Google Groups "isar-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email to isar-users+unsubscribe@googlegroups.com.
To view this discussion visit https://groups.google.com/d/msgid/isar-users/20260923143350.2086040-1-felix.moessbauer%40siemens.com.
next reply other threads:[~2026-09-23 14:34 UTC|newest]
Thread overview: 2+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-23 14:33 'Felix Moessbauer' via isar-users [this message]
2026-09-29 8:07 ` Zhihang Wei
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260923143350.2086040-1-felix.moessbauer@siemens.com \
--to=isar-users@googlegroups.com \
--cc=felix.moessbauer@siemens.com \
--cc=jan.kiszka@siemens.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox