sandbox: separate tmpfs function from op
This is useful in the implementation of various other ops. Signed-off-by: Ophestra <cat@gensokyo.uk>
This commit is contained in:
parent
f1002157a5
commit
5d9e669d97
@ -79,3 +79,17 @@ func bindMount(src, dest string, flags int) error {
|
|||||||
return fmsg.WrapErrorSuffix(syscall.Mount(source, target, "", mf, ""),
|
return fmsg.WrapErrorSuffix(syscall.Mount(source, target, "", mf, ""),
|
||||||
fmt.Sprintf("cannot bind %q on %q:", src, dest))
|
fmt.Sprintf("cannot bind %q on %q:", src, dest))
|
||||||
}
|
}
|
||||||
|
|
||||||
|
func mountTmpfs(name string, size int, perm os.FileMode) error {
|
||||||
|
target := toSysroot(name)
|
||||||
|
if err := os.MkdirAll(target, perm); err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
opt := fmt.Sprintf("mode=%#o", perm)
|
||||||
|
if size > 0 {
|
||||||
|
opt += fmt.Sprintf(",size=%d", size)
|
||||||
|
}
|
||||||
|
return fmsg.WrapErrorSuffix(syscall.Mount("tmpfs", target, "tmpfs",
|
||||||
|
syscall.MS_NOSUID|syscall.MS_NODEV, opt),
|
||||||
|
fmt.Sprintf("cannot mount tmpfs on %q:", name))
|
||||||
|
}
|
||||||
|
@ -75,7 +75,7 @@ func init() { gob.Register(new(MountTmpfs)) }
|
|||||||
type MountTmpfs struct {
|
type MountTmpfs struct {
|
||||||
Path string
|
Path string
|
||||||
Size int
|
Size int
|
||||||
Mode os.FileMode
|
Perm os.FileMode
|
||||||
}
|
}
|
||||||
|
|
||||||
func (t *MountTmpfs) apply() error {
|
func (t *MountTmpfs) apply() error {
|
||||||
@ -87,22 +87,12 @@ func (t *MountTmpfs) apply() error {
|
|||||||
return fmsg.WrapError(syscall.EBADE,
|
return fmsg.WrapError(syscall.EBADE,
|
||||||
fmt.Sprintf("size %d out of bounds", t.Size))
|
fmt.Sprintf("size %d out of bounds", t.Size))
|
||||||
}
|
}
|
||||||
target := toSysroot(t.Path)
|
return mountTmpfs(t.Path, t.Size, t.Perm)
|
||||||
if err := os.MkdirAll(target, 0755); err != nil {
|
|
||||||
return err
|
|
||||||
}
|
|
||||||
opt := fmt.Sprintf("mode=%#o", t.Mode)
|
|
||||||
if t.Size > 0 {
|
|
||||||
opt += fmt.Sprintf(",size=%d", t.Mode)
|
|
||||||
}
|
|
||||||
return fmsg.WrapErrorSuffix(syscall.Mount("tmpfs", target, "tmpfs",
|
|
||||||
syscall.MS_NOSUID|syscall.MS_NODEV, opt),
|
|
||||||
fmt.Sprintf("cannot mount tmpfs on %q:", t.Path))
|
|
||||||
}
|
}
|
||||||
|
|
||||||
func (t *MountTmpfs) Is(op Op) bool { vt, ok := op.(*MountTmpfs); return ok && *t == *vt }
|
func (t *MountTmpfs) Is(op Op) bool { vt, ok := op.(*MountTmpfs); return ok && *t == *vt }
|
||||||
func (t *MountTmpfs) String() string { return fmt.Sprintf("tmpfs on %q size %d", t.Path, t.Size) }
|
func (t *MountTmpfs) String() string { return fmt.Sprintf("tmpfs on %q size %d", t.Path, t.Size) }
|
||||||
func (f *Ops) Tmpfs(dest string, size int, mode os.FileMode) *Ops {
|
func (f *Ops) Tmpfs(dest string, size int, perm os.FileMode) *Ops {
|
||||||
*f = append(*f, &MountTmpfs{dest, size, mode})
|
*f = append(*f, &MountTmpfs{dest, size, perm})
|
||||||
return f
|
return f
|
||||||
}
|
}
|
||||||
|
Loading…
Reference in New Issue
Block a user