public inbox for isar-users@googlegroups.com
 help / color / mirror / Atom feed
* [PATCH 1/1] isar-mounts: mount /run as tmpfs for systemd execution in chroot
@ 2026-09-23 14:33 'Felix Moessbauer' via isar-users
  2026-09-29  8:07 ` Zhihang Wei
  0 siblings, 1 reply; 2+ messages in thread
From: 'Felix Moessbauer' via isar-users @ 2026-09-23 14:33 UTC (permalink / raw)
  To: isar-users; +Cc: Felix Moessbauer, Jan Kiszka

When running systemd inside the chroot, it might access /run and place
files there. These can have ownerships (like 0000) which require DAC
capabilities for traversing and removing. As this is tricky to achieve
across all cleanup code, we stick to the systemd file system hierarchy
and mount /run as a tmpfs. By that, all files below it will
automatically be dropped when leaving the namespace.

This solves cleanup issues on rootless like:
  find: '<...>/rootfs/run/systemd/dissect-root': Permission denied

As we anyways cleanup the /run in do_rootfs_finalize (image only), this
does not change the content of the image. However, it improves the
reproduciblity of our internal rootfs' which can improve caching.

Reported-by: Jan Kiszka <jan.kiszka@siemens.com>
Signed-off-by: Felix Moessbauer <felix.moessbauer@siemens.com>
---
 meta/classes-global/base.bbclass | 4 ++++
 1 file changed, 4 insertions(+)

diff --git a/meta/classes-global/base.bbclass b/meta/classes-global/base.bbclass
index 8f81ab70..3d5d1c12 100644
--- a/meta/classes-global/base.bbclass
+++ b/meta/classes-global/base.bbclass
@@ -399,6 +399,10 @@ def insert_isar_mounts(d, rootfs, mounts):
         lines.append('mount -t devpts -o noexec,nosuid,uid=5,mode=620,ptmxmode=666 none {}/dev/pts'.format(rootfs))
         lines.append('( cd {}/dev; ln -sf pts/ptmx . )'.format(rootfs))
         lines.append('mount -t tmpfs none {}/dev/shm'.format(rootfs))
+        # required by systemd file-system hierarchy
+        lines.append('mount -t tmpfs -o mode=0755 tmpfs {}/run'.format(rootfs))
+        # required by Debian policy 9.1.4
+        lines.append('mkdir {}/run/lock'.format(rootfs))
         lines.append('mount -o bind /dev/random {}/dev/random'.format(rootfs))
         lines.append('mount -o bind /dev/urandom {}/dev/urandom'.format(rootfs))
         lines.append('mount -t proc none {}/proc'.format(rootfs))
-- 
2.55.0

-- 
You received this message because you are subscribed to the Google Groups "isar-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email to isar-users+unsubscribe@googlegroups.com.
To view this discussion visit https://groups.google.com/d/msgid/isar-users/20260923143350.2086040-1-felix.moessbauer%40siemens.com.

^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2026-09-29  8:07 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-09-23 14:33 [PATCH 1/1] isar-mounts: mount /run as tmpfs for systemd execution in chroot 'Felix Moessbauer' via isar-users
2026-09-29  8:07 ` Zhihang Wei

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox