public inbox for isar-users@googlegroups.com
 help / color / mirror / Atom feed
From: "'Felix Moessbauer' via isar-users" <isar-users@googlegroups.com>
To: isar-users@googlegroups.com
Cc: Felix Moessbauer <felix.moessbauer@siemens.com>,
	Jan Kiszka <jan.kiszka@siemens.com>
Subject: [PATCH 1/1] isar-mounts: mount /run as tmpfs for systemd execution in chroot
Date: Wed, 23 Sep 2026 16:33:50 +0200	[thread overview]
Message-ID: <20260923143350.2086040-1-felix.moessbauer@siemens.com> (raw)

When running systemd inside the chroot, it might access /run and place
files there. These can have ownerships (like 0000) which require DAC
capabilities for traversing and removing. As this is tricky to achieve
across all cleanup code, we stick to the systemd file system hierarchy
and mount /run as a tmpfs. By that, all files below it will
automatically be dropped when leaving the namespace.

This solves cleanup issues on rootless like:
  find: '<...>/rootfs/run/systemd/dissect-root': Permission denied

As we anyways cleanup the /run in do_rootfs_finalize (image only), this
does not change the content of the image. However, it improves the
reproduciblity of our internal rootfs' which can improve caching.

Reported-by: Jan Kiszka <jan.kiszka@siemens.com>
Signed-off-by: Felix Moessbauer <felix.moessbauer@siemens.com>
---
 meta/classes-global/base.bbclass | 4 ++++
 1 file changed, 4 insertions(+)

diff --git a/meta/classes-global/base.bbclass b/meta/classes-global/base.bbclass
index 8f81ab70..3d5d1c12 100644
--- a/meta/classes-global/base.bbclass
+++ b/meta/classes-global/base.bbclass
@@ -399,6 +399,10 @@ def insert_isar_mounts(d, rootfs, mounts):
         lines.append('mount -t devpts -o noexec,nosuid,uid=5,mode=620,ptmxmode=666 none {}/dev/pts'.format(rootfs))
         lines.append('( cd {}/dev; ln -sf pts/ptmx . )'.format(rootfs))
         lines.append('mount -t tmpfs none {}/dev/shm'.format(rootfs))
+        # required by systemd file-system hierarchy
+        lines.append('mount -t tmpfs -o mode=0755 tmpfs {}/run'.format(rootfs))
+        # required by Debian policy 9.1.4
+        lines.append('mkdir {}/run/lock'.format(rootfs))
         lines.append('mount -o bind /dev/random {}/dev/random'.format(rootfs))
         lines.append('mount -o bind /dev/urandom {}/dev/urandom'.format(rootfs))
         lines.append('mount -t proc none {}/proc'.format(rootfs))
-- 
2.55.0

-- 
You received this message because you are subscribed to the Google Groups "isar-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email to isar-users+unsubscribe@googlegroups.com.
To view this discussion visit https://groups.google.com/d/msgid/isar-users/20260923143350.2086040-1-felix.moessbauer%40siemens.com.

             reply	other threads:[~2026-09-23 14:34 UTC|newest]

Thread overview: 2+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-23 14:33 'Felix Moessbauer' via isar-users [this message]
2026-09-29  8:07 ` Zhihang Wei

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260923143350.2086040-1-felix.moessbauer@siemens.com \
    --to=isar-users@googlegroups.com \
    --cc=felix.moessbauer@siemens.com \
    --cc=jan.kiszka@siemens.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox