* [PATCH 1/1] isar-mounts: mount /run as tmpfs for systemd execution in chroot
@ 2026-09-23 14:33 'Felix Moessbauer' via isar-users
2026-09-29 8:07 ` Zhihang Wei
0 siblings, 1 reply; 2+ messages in thread
From: 'Felix Moessbauer' via isar-users @ 2026-09-23 14:33 UTC (permalink / raw)
To: isar-users; +Cc: Felix Moessbauer, Jan Kiszka
When running systemd inside the chroot, it might access /run and place
files there. These can have ownerships (like 0000) which require DAC
capabilities for traversing and removing. As this is tricky to achieve
across all cleanup code, we stick to the systemd file system hierarchy
and mount /run as a tmpfs. By that, all files below it will
automatically be dropped when leaving the namespace.
This solves cleanup issues on rootless like:
find: '<...>/rootfs/run/systemd/dissect-root': Permission denied
As we anyways cleanup the /run in do_rootfs_finalize (image only), this
does not change the content of the image. However, it improves the
reproduciblity of our internal rootfs' which can improve caching.
Reported-by: Jan Kiszka <jan.kiszka@siemens.com>
Signed-off-by: Felix Moessbauer <felix.moessbauer@siemens.com>
---
meta/classes-global/base.bbclass | 4 ++++
1 file changed, 4 insertions(+)
diff --git a/meta/classes-global/base.bbclass b/meta/classes-global/base.bbclass
index 8f81ab70..3d5d1c12 100644
--- a/meta/classes-global/base.bbclass
+++ b/meta/classes-global/base.bbclass
@@ -399,6 +399,10 @@ def insert_isar_mounts(d, rootfs, mounts):
lines.append('mount -t devpts -o noexec,nosuid,uid=5,mode=620,ptmxmode=666 none {}/dev/pts'.format(rootfs))
lines.append('( cd {}/dev; ln -sf pts/ptmx . )'.format(rootfs))
lines.append('mount -t tmpfs none {}/dev/shm'.format(rootfs))
+ # required by systemd file-system hierarchy
+ lines.append('mount -t tmpfs -o mode=0755 tmpfs {}/run'.format(rootfs))
+ # required by Debian policy 9.1.4
+ lines.append('mkdir {}/run/lock'.format(rootfs))
lines.append('mount -o bind /dev/random {}/dev/random'.format(rootfs))
lines.append('mount -o bind /dev/urandom {}/dev/urandom'.format(rootfs))
lines.append('mount -t proc none {}/proc'.format(rootfs))
--
2.55.0
--
You received this message because you are subscribed to the Google Groups "isar-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email to isar-users+unsubscribe@googlegroups.com.
To view this discussion visit https://groups.google.com/d/msgid/isar-users/20260923143350.2086040-1-felix.moessbauer%40siemens.com.
^ permalink raw reply [flat|nested] 2+ messages in thread* Re: [PATCH 1/1] isar-mounts: mount /run as tmpfs for systemd execution in chroot
2026-09-23 14:33 [PATCH 1/1] isar-mounts: mount /run as tmpfs for systemd execution in chroot 'Felix Moessbauer' via isar-users
@ 2026-09-29 8:07 ` Zhihang Wei
0 siblings, 0 replies; 2+ messages in thread
From: Zhihang Wei @ 2026-09-29 8:07 UTC (permalink / raw)
To: Felix Moessbauer, isar-users; +Cc: Jan Kiszka
Applied to next, thanks.
Zhihang
On 9/23/26 16:33, 'Felix Moessbauer' via isar-users wrote:
> When running systemd inside the chroot, it might access /run and place
> files there. These can have ownerships (like 0000) which require DAC
> capabilities for traversing and removing. As this is tricky to achieve
> across all cleanup code, we stick to the systemd file system hierarchy
> and mount /run as a tmpfs. By that, all files below it will
> automatically be dropped when leaving the namespace.
>
> This solves cleanup issues on rootless like:
> find: '<...>/rootfs/run/systemd/dissect-root': Permission denied
>
> As we anyways cleanup the /run in do_rootfs_finalize (image only), this
> does not change the content of the image. However, it improves the
> reproduciblity of our internal rootfs' which can improve caching.
>
> Reported-by: Jan Kiszka <jan.kiszka@siemens.com>
> Signed-off-by: Felix Moessbauer <felix.moessbauer@siemens.com>
> ---
> meta/classes-global/base.bbclass | 4 ++++
> 1 file changed, 4 insertions(+)
>
> diff --git a/meta/classes-global/base.bbclass b/meta/classes-global/base.bbclass
> index 8f81ab70..3d5d1c12 100644
> --- a/meta/classes-global/base.bbclass
> +++ b/meta/classes-global/base.bbclass
> @@ -399,6 +399,10 @@ def insert_isar_mounts(d, rootfs, mounts):
> lines.append('mount -t devpts -o noexec,nosuid,uid=5,mode=620,ptmxmode=666 none {}/dev/pts'.format(rootfs))
> lines.append('( cd {}/dev; ln -sf pts/ptmx . )'.format(rootfs))
> lines.append('mount -t tmpfs none {}/dev/shm'.format(rootfs))
> + # required by systemd file-system hierarchy
> + lines.append('mount -t tmpfs -o mode=0755 tmpfs {}/run'.format(rootfs))
> + # required by Debian policy 9.1.4
> + lines.append('mkdir {}/run/lock'.format(rootfs))
> lines.append('mount -o bind /dev/random {}/dev/random'.format(rootfs))
> lines.append('mount -o bind /dev/urandom {}/dev/urandom'.format(rootfs))
> lines.append('mount -t proc none {}/proc'.format(rootfs))
--
You received this message because you are subscribed to the Google Groups "isar-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email to isar-users+unsubscribe@googlegroups.com.
To view this discussion visit https://groups.google.com/d/msgid/isar-users/64f00659-3c6a-4b57-96c7-3499e6ce65a8%40ilbers.de.
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2026-09-29 8:07 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-09-23 14:33 [PATCH 1/1] isar-mounts: mount /run as tmpfs for systemd execution in chroot 'Felix Moessbauer' via isar-users
2026-09-29 8:07 ` Zhihang Wei
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox